Getting Started
Core Features
How-To Guides
Configuration
Integrations
Troubleshooting
Enterprise organizations on the Enterprise plan can configure SAML Single Sign-On (SSO) and SCIM Directory Sync to streamline team access and management. SAML SSO allows your team members to log in using your organization’s identity provider, while SCIM Directory Sync automatically provisions and deprovisions user accounts based on your directory settings.
Important
Both SAML SSO and SCIM Directory Sync require an Enterprise plan and appropriate workspace permissions (workspaces.write).
The following identity providers are fully supported for both SAML SSO and SCIM user provisioning:
| Okta | okta | okta-scim-v2 | Metadata URL |
| Entra ID (formerly Azure AD) | azure | azure-scim-v2 | App Federation Metadata URL |
google | google | XML Metadata File |
Note
Supported providers: Okta, Entra ID (formerly Azure AD), Google.
Setting up SAML SSO allows members of your organization to authenticate securely using your identity provider.
Okta, Entra ID, or Google).Directory Sync using SCIM automatically provisions new users and deprovisions removed or deactivated users from your workspace.
Okta, Entra ID, or Google).Tip
When a user is activated or created in your identity provider, an invitation or workspace membership is automatically generated. When deactivated or deleted, their workspace access is immediately revoked.
If you need to update or remove your SSO or SCIM configurations, you can do so directly from the Security settings page.
Caution
Removing SAML or SCIM is irreversible and will immediately disconnect your identity provider integration, revoking enforced domain sign-in rules.
To remove a connection:
confirm remove saml or confirm remove scim) to confirm the action.