SSO is managed per workspace and only a workspace
admin can configure it. Connections use OIDC - point them at any provider that publishes a standard discovery document (Okta, Entra ID, Google, Auth0, and others).Before you start
1
Be a workspace admin
Only an
admin can manage SSO. See Workspaces and teams for roles.2
Register an OIDC app with your IdP
Create an OIDC application in your identity provider and note its issuer URL, client ID, and client secret.
Set up a connection
1
Create the connection
Send your issuer, client credentials, and the email domain it covers. Only A
issuer, client_id, client_secret, and email_domain are required.201 returns the connection. Note domain_verified is false and a verification_token is included for the next step. The client_secret is never returned.2
Verify domain ownership
A connection cannot log anyone in until you prove you own its domain. Add a DNS
TXT record, then call verify.Create this record with your DNS provider:Then confirm it:
DNS changes can take time to propagate. If the record is not visible yet, the response returns
domain_verified: false with the exact record_host and record_value to set. Wait and retry.3
Test the connection
Check that your issuer’s discovery endpoint is reachable before you rely on it. Pass just the issuer.
Manage connections
List connections
List connections
Returns every SSO connection in your current workspace. Admin only.
Update a connection
Update a connection
Send the connection
id and the fields to change. Leave client_secret empty to keep the stored one. Admin only.Changing
email_domain resets domain_verified to false. You will need to verify the new domain again.Delete a connection
Delete a connection
Pass the connection id as the
id query parameter. Admin only.Next steps
Workspaces and teams
Manage members and roles inside your workspace.
Authentication
How API keys and bearer auth work.