User Guide
Single Sign-On (SSO)
Configure OIDC-based SSO with your identity provider. Professional and Enterprise tiers.
Supported providers#
- Azure AD (Entra ID) — Microsoft OIDC with group claims.
- Google Workspace — Google OIDC.
- Generic OIDC — any OIDC-compliant identity provider (Okta, Auth0, Keycloak, etc.).
Configuration#
- Go to Settings → SSO.
- Click "Add Provider" and select the provider type.
- Enter the Client ID, Client Secret, and Discovery URL (or Issuer URL).
- Set the Redirect URI to match what's configured in your IdP.
- Click "Test Configuration" to verify the OIDC flow works.
- Enable the provider for users.
Allowed domains
The SSO allowed domains are auto-populated from your license's customer email domain. Only users with email addresses in allowed domains can log in via SSO.
Group sync#
Map identity provider groups to document permissions. When users log in via SSO, their group memberships sync automatically, granting access to documents shared with those groups.
- Azure AD — fetches groups via the Microsoft Graph API using the service principal.
- Group mappings — map each IdP group ID to a principal string used in document permissions.
- Per-user override — individual users can opt out of group sync.
Tip
Group sync is additive — it never removes direct user-level permissions. Users always retain access to documents explicitly shared with their email.