User Guide

Single Sign-On (SSO)

Configure OIDC-based SSO with your identity provider. Professional and Enterprise tiers.

Supported providers#

  • Azure AD (Entra ID) — Microsoft OIDC with group claims.
  • Google Workspace — Google OIDC.
  • Generic OIDC — any OIDC-compliant identity provider (Okta, Auth0, Keycloak, etc.).

Configuration#

  1. Go to Settings → SSO.
  2. Click "Add Provider" and select the provider type.
  3. Enter the Client ID, Client Secret, and Discovery URL (or Issuer URL).
  4. Set the Redirect URI to match what's configured in your IdP.
  5. Click "Test Configuration" to verify the OIDC flow works.
  6. Enable the provider for users.
Allowed domains
The SSO allowed domains are auto-populated from your license's customer email domain. Only users with email addresses in allowed domains can log in via SSO.

Group sync#

Map identity provider groups to document permissions. When users log in via SSO, their group memberships sync automatically, granting access to documents shared with those groups.

  • Azure AD — fetches groups via the Microsoft Graph API using the service principal.
  • Group mappings — map each IdP group ID to a principal string used in document permissions.
  • Per-user override — individual users can opt out of group sync.
Tip
Group sync is additive — it never removes direct user-level permissions. Users always retain access to documents explicitly shared with their email.