Single sign-on (SSO)
Settings → Organization → Security → Single sign-on. Visible to admins who can manage security.
- OIDC: Tenant ID (Microsoft) or Client ID, plus a client secret, and — for a custom provider — the Issuer URL.
- SAML: the IdP metadata (a URL or an XML file), or manually the IdP SSO URL, IdP entity ID and the IdP certificate.
Set up OIDC
1
Pick a provider
Under Authentication, choose Microsoft, Google or Custom.
2
Enter provider details
- Microsoft: Tenant ID, Client ID.
- Google: Client ID.
- Custom: Issuer URL, Client ID.
3
Register the redirect URI
Copy the Redirect URI shown and add it in your identity provider’s app registration.
4
Test, then turn on
Use Test to confirm the secret is accepted, then switch the provider on. Use Use [provider] for login to make it the active protocol.
Set up SAML
1
Import metadata
Paste a Metadata URL or upload a Metadata file, then Parse metadata to fill the fields automatically — or enter them by hand: IdP SSO URL, IdP entity ID, and the IdP certificate.
2
Register the ACS URL
Copy the Assertion Consumer Service (ACS) URL and register it as the Reply URL in your identity provider. The SP entity ID defaults to the ACS URL — override it only if your IdP requires a different identifier.
3
Optional claims and signing
Set the Email claim and Name claim if your IdP uses non-standard attribute names, choose the NameID format (Email address, Persistent, Transient or Unspecified), and require signed assertions and/or a signed authentication response if your IdP supports it.
4
Test, then turn on
Test the configuration, then switch SAML on and set it as the login method.
Require SSO for non-admin users
Once a protocol is live, turn on Require SSO for non-admin users under Login policy. Only organization admins can still sign in with email and password; everyone else must use SSO.Two-factor authentication (2FA)
Every user can enable 2FA for their own account from Settings → Account → Two-Factor Authentication (2FA).1
Start setup
Click Setup 2FA.
2
Scan the QR code
Scan it with your authenticator app (any TOTP app), or enter the secret manually.
3
Verify
Enter the code your app shows to confirm setup.
4
Save your backup codes
Download the backup codes shown — they’re displayed only once. Store them somewhere safe; you’ll need one if you lose access to your authenticator app.