Skip to main content
SSO lets people sign in through your identity provider, OIDC or SAML, with their work account. People who already have accounts keep signing in as before. SSO creates a new account only for an address on a domain you have verified.

Verify your domain

1

Add the domain

As an org admin, open Integrations, then the SSO tab. Under Verified domains, enter the domain, for example example.com, and click Add domain. Tick Also cover its subdomains if people sign in with addresses such as name@eu.example.com.
2

Publish the TXT record

The domain’s row shows a Name and a Value. At your DNS provider, create a TXT record with the name _sreagent-challenge.example.com (enter only _sreagent-challenge if your provider adds the domain for you) and the sreagent-verification=... value shown.
3

Verify

Click Verify. New records can take up to an hour to appear. When it succeeds the badge reads Verified.
A code that is never verified expires after 30 days. Click New code for another. Public email providers and throwaway-mailbox domains cannot be verified. SRE Agent checks every verified domain once a day. If the record is missing, the badge shows Failing since a date and your admins are emailed the date it will lapse. If it is still missing seven days after the first miss, the domain shows Lapsed and SSO stops creating new accounts on it. Nobody who already has an account loses it. Publish the record again and click Verify or Check now to restore it. Any number of organizations can add a domain, but only one can hold it verified. With Keep our email domains invitation-only on, a verified domain also sends join requests to your organization.

Add the provider

1

Open Add Provider

On the SSO tab, click Add Provider and enter a Name, then choose the Provider Type.
2

OIDC

Register an application in your identity provider with the Redirect URI shown in the OIDC Setup Guide on the tab. Enter its Client ID, Client Secret and Discovery URL, the base issuer URL.
3

SAML

Save the provider first, then reopen it with Edit to copy the ACS URL and Entity ID into your identity provider. Paste back its IdP SSO URL, IdP Entity ID and IdP Certificate (PEM).
4

Map roles

Set the Group attribute name and add Group → role mapping rows to give each group a role. The highest matching role wins and is re-applied at every sign-in. Default role controls what happens when no group matches. Leave it on Leave unchanged unless you want sign-in to set roles. No sync can remove your organization’s last admin.
5

Enable

Save, then click Enable on the provider’s row.

Sign in with SSO

On the sign-in page, enter your organization slug under Sign in with SSO and click Continue. Your providers appear as buttons. To skip the slug, use https://sreagent.app/login?org=<your-org>, or give your identity provider’s portal the start URL that Edit shows for the provider. People you disable or remove are refused at sign-in, whichever protocol they use. If Verified domains is empty, the tab warns that nobody new can be created at sign-in until you verify one. Invited people and existing members are not affected, and your group mappings set roles at each sign-in.