Skip to main content
SSO lets your team sign in to Encrata with your existing identity provider over OIDC. You add a connection for your email domain, verify you own that domain, then optionally require everyone on it to log in through your IdP. This guide walks through the full setup.
SSO is managed per workspace and only a workspace admin can configure it. Connections use OIDC - point them at any provider that publishes a standard discovery document (Okta, Entra ID, Google, Auth0, and others).

Before you start

1

Be a workspace admin

Only an admin can manage SSO. See Workspaces and teams for roles.
2

Register an OIDC app with your IdP

Create an OIDC application in your identity provider and note its issuer URL, client ID, and client secret.

Set up a connection

1

Create the connection

Send your issuer, client credentials, and the email domain it covers. Only issuer, client_id, client_secret, and email_domain are required.
A 201 returns the connection. Note domain_verified is false and a verification_token is included for the next step. The client_secret is never returned.
2

Verify domain ownership

A connection cannot log anyone in until you prove you own its domain. Add a DNS TXT record, then call verify.Create this record with your DNS provider:Then confirm it:
DNS changes can take time to propagate. If the record is not visible yet, the response returns domain_verified: false with the exact record_host and record_value to set. Wait and retry.
3

Test the connection

Check that your issuer’s discovery endpoint is reachable before you rely on it. Pass just the issuer.
This endpoint always returns 200. Read the success field - a failure comes back as { "success": false, "error": "..." }.

Manage connections

Returns every SSO connection in your current workspace. Admin only.
Send the connection id and the fields to change. Leave client_secret empty to keep the stored one. Admin only.
Changing email_domain resets domain_verified to false. You will need to verify the new domain again.
Pass the connection id as the id query parameter. Admin only.

Next steps

Workspaces and teams

Manage members and roles inside your workspace.

Authentication

How API keys and bearer auth work.