> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On (SSO)

> Set up and manage Single Sign-On (SSO) for your Bijection team

<Info>
  Single Sign-On is only available on Bijection Business and Enterprise.
</Info>

Single Sign-On (SSO) allows your team to authenticate with Bijection using your
organization's identity provider (IdP). Once configured, team members can sign
in to Bijection through your IdP instead of using individual credentials.

## Finding the settings

SSO is configured on the
[Team Authentication page](https://console.bijection.com),
under **Team Settings → Team Authentication**.

Two of its sections cover SSO:

* **Authentication Domains** — the email domains your team owns. SSO only
  manages members whose account uses one of these domains.
* **Single sign-on** — your identity provider connection.

<Frame>
  <img src="https://mintcdn.com/bijection-95ba84d3/f-zeSQU2ke_jvHT0/screenshots/pages_team_authentication_sso_sections.png?fit=max&auto=format&n=f-zeSQU2ke_jvHT0&q=85&s=92344b1f69631688f6654284479cbf6e" alt="The Authentication Domains and Single sign-on sections before anything is configured" width="1472" height="772" data-path="screenshots/pages_team_authentication_sso_sections.png" />
</Frame>

## Setting up SSO

### 1. Verify a domain

Each connection is attached to a domain you own, so start by verifying yours.
Select **Add a domain** in the **Authentication Domains** section. Bijection opens
a separate configuration page in a new tab, where you enter the domain and
complete the DNS verification.

Verification is not instant. A domain shows as **Pending** until your DNS record
is picked up, and **Verified** once it is. You can re-open **Add a domain** at
any time to check on a pending domain.

<Frame>
  <img src="https://mintcdn.com/bijection-95ba84d3/z1QH_TSyFd7Yth27/screenshots/pages_team_authentication_domains.png?fit=max&auto=format&n=z1QH_TSyFd7Yth27&q=85&s=a94d55a05787a6f77302da977522941d" alt="The Authentication Domains section listing a verified and a pending domain" width="1472" height="532" data-path="screenshots/pages_team_authentication_domains.png" />
</Frame>

<Warning>
  Your own Bijection account needs a
  [verified email](https://console.bijection.com) on one of these domains,
  otherwise you won't be able to log in through SSO yourself. When none of your
  verified emails match, the section shows a warning next to its title.
</Warning>

### 2. Connect your identity provider

Once a domain is verified, select **Configure** in the **Single sign-on**
section. Bijection opens a separate configuration page in a new tab, where you pick
your identity provider and follow its setup instructions.

<Frame>
  <img src="https://mintcdn.com/bijection-95ba84d3/f-zeSQU2ke_jvHT0/screenshots/pages_team_authentication_single_sign_on.png?fit=max&auto=format&n=f-zeSQU2ke_jvHT0&q=85&s=b59db23005919279645681fbe910ab3a" alt="The Single sign-on section before a connection has been configured" width="1472" height="432" data-path="screenshots/pages_team_authentication_single_sign_on.png" />
</Frame>

When you come back, the connection appears in the section with its status:

* **Active** — team members can log in through this identity provider.
* **Inactive** — the connection exists but isn't finished. Re-open it with **⋮ →
  Manage** to complete the remaining steps with your identity provider.

<Frame>
  <img src="https://mintcdn.com/bijection-95ba84d3/f-zeSQU2ke_jvHT0/screenshots/pages_team_authentication_single_sign_on_configured.png?fit=max&auto=format&n=f-zeSQU2ke_jvHT0&q=85&s=5b71bcd4b2126909977f4b105a2946ff" alt="The Single sign-on section with an active Okta SAML connection" width="1472" height="448" data-path="screenshots/pages_team_authentication_single_sign_on_configured.png" />
</Frame>

### 3. Test the connection

Log out and log back in through your identity provider to confirm the connection
works before requiring SSO for the whole team.

## Managing the connection

Use the **⋮** menu next to the connection to manage it:

<Frame>
  <img src="https://mintcdn.com/bijection-95ba84d3/z1QH_TSyFd7Yth27/screenshots/pages_team_authentication_single_sign_on_menu.png?fit=max&auto=format&n=z1QH_TSyFd7Yth27&q=85&s=fd4c06868437a12e37aecabd5e32c322" alt="The connection menu with Manage, Renew certificate, and Disable Single sign-on" width="1472" height="608" data-path="screenshots/pages_team_authentication_single_sign_on_menu.png" />
</Frame>

* **⋮ → Manage** re-opens the configuration page for this connection.
* **⋮ → Renew certificate** walks you through replacing a signing certificate
  before it expires.
* **⋮ → Disable Single sign-on** removes the connection. Team members can no
  longer log in through your identity provider. Your verified domains are
  unaffected.

## Require Single Sign-On

Once a connection is active, you can **require** SSO for the team by checking
**Require SSO to access team**. The console asks you to confirm before saving.

<Frame>
  <img src="https://mintcdn.com/bijection-95ba84d3/f-zeSQU2ke_jvHT0/screenshots/pages_team_authentication_require_sso.png?fit=max&auto=format&n=f-zeSQU2ke_jvHT0&q=85&s=13870ade97f379d39e83aab6c38550bc" alt="The confirmation dialog for requiring SSO to access the team" width="2048" height="1400" data-path="screenshots/pages_team_authentication_require_sso.png" />
</Frame>

When this setting is on:

* All team members must authenticate through your identity provider to access
  this team. This applies to both the console and the CLI.
* Members cannot use other authentication methods to access the team.

This only applies to the team that has SSO enabled. Members can still use other
login methods to access any other Bijection teams they belong to.

<Warning>
  Test your SSO configuration before turning this on. If the connection doesn't
  work, nobody can access the team, including you.
</Warning>

## Customizing your domain policy

By default, all Bijection users that sign in with your verified SSO domain will be
required to log in with SSO to use Bijection if they are signing in with an email
address that uses your verified domain.

To configure a custom domain policy, such as allowing users to login with other
sign-on methods, contact Bijection support.

These settings will be available for self-serve configuration in the future.

## Who can configure SSO

Team Admins can do everything on this page. Team Developers can see the
configuration but not change it. With
[custom roles](/team-management/custom-roles) you can grant the individual
[role actions](/team-management/role-actions#sso): `sso:view`, `sso:enable`,
`sso:update`, `sso:disable`, and the `team:domain:*` actions that cover the
**Authentication Domains** section.
