> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up single sign-on

> Verify your domain, connect an OIDC or SAML identity provider, map groups to roles, and sign in with SSO.

export const Plan = ({tier}) => <Badge color="blue">{tier} plan</Badge>;

<Plan tier="Business" />

SSO lets people sign in through your identity provider, OIDC or SAML, with their work account. People who already have accounts keep signing in as before. SSO creates a new account only for an address on a domain you have verified.

## Verify your domain

<Steps>
  <Step title="Add the domain">
    As an org admin, open **Integrations**, then the **SSO** tab. Under **Verified domains**, enter
    the domain, for example `example.com`, and click **Add domain**. Tick **Also cover its
    subdomains** if people sign in with addresses such as `name@eu.example.com`.
  </Step>

  <Step title="Publish the TXT record">
    The domain's row shows a **Name** and a **Value**. At your DNS provider, create a TXT record
    with the name `_sreagent-challenge.example.com` (enter only `_sreagent-challenge` if your
    provider adds the domain for you) and the `sreagent-verification=...` value shown.
  </Step>

  <Step title="Verify">
    Click **Verify**. New records can take up to an hour to appear. When it succeeds the badge reads
    **Verified**.
  </Step>
</Steps>

A code that is never verified expires after 30 days. Click **New code** for another. Public email providers and throwaway-mailbox domains cannot be verified.

SRE Agent checks every verified domain once a day. If the record is missing, the badge shows **Failing since** a date and your admins are emailed the date it will lapse. If it is still missing seven days after the first miss, the domain shows **Lapsed** and SSO stops creating new accounts on it. Nobody who already has an account loses it. Publish the record again and click **Verify** or **Check now** to restore it.

Any number of organizations can add a domain, but only one can hold it verified.

With **Keep our email domains invitation-only** on, a verified domain also sends join requests to your organization.

## Add the provider

<Steps>
  <Step title="Open Add Provider">
    On the **SSO** tab, click **Add Provider** and enter a **Name**, then choose the **Provider
    Type**.
  </Step>

  <Step title="OIDC">
    Register an application in your identity provider with the **Redirect URI** shown in the **OIDC
    Setup Guide** on the tab. Enter its **Client ID**, **Client Secret** and **Discovery URL**, the
    base issuer URL.
  </Step>

  <Step title="SAML">
    Save the provider first, then reopen it with **Edit** to copy the **ACS URL** and **Entity ID**
    into your identity provider. Paste back its **IdP SSO URL**, **IdP Entity ID** and **IdP
    Certificate (PEM)**.
  </Step>

  <Step title="Map roles">
    Set the **Group attribute name** and add **Group → role mapping** rows to give each group a
    role. The highest matching role wins and is re-applied at every sign-in. **Default role**
    controls what happens when no group matches. Leave it on **Leave unchanged** unless you want
    sign-in to set roles. No sync can remove your organization's last admin.
  </Step>

  <Step title="Enable">Save, then click **Enable** on the provider's row.</Step>
</Steps>

## Sign in with SSO

On the sign-in page, enter your organization slug under **Sign in with SSO** and click **Continue**. Your providers appear as buttons. To skip the slug, use `https://sreagent.app/login?org=<your-org>`, or give your identity provider's portal the start URL that **Edit** shows for the provider.

People you disable or remove are refused at sign-in, whichever protocol they use.

If **Verified domains** is empty, the tab warns that nobody new can be created at sign-in until you verify one. Invited people and existing members are not affected, and your group mappings set roles at each sign-in.

## Related

* [Sign in and join your team](/guides/administer/sign-in-and-joining-your-team): how people join without SSO.
* [Manage people and roles](/guides/administer/organizations-and-roles): the roles your group mappings assign.
* [Plan matrix](/guides/reference/plan-matrix): which plans include SSO.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.