Enforce SSO
Last updated: September 9, 2026
Enforce SSO
When "Enforce SSO" is enabled, members of this tenant can only log in via SSO. Password login is disabled.
Settings → SAML SSO → "Enforce SSO"
Caution: Ensure that SSO is working correctly before enforcing it. The tenant owner can deactivate SSO enforcement at any time.
Auto-Provisioning
When "Auto-Provisioning" is enabled, users are automatically created upon their first SSO login:
- Email: From SAML assertion
- Name: From SAML assertion (fallback: email prefix)
- Role: Configurable (default: "Agent")
- Status: Immediately active (verified)
- Password: None (SSO users do not have a password)
If Auto-Provisioning is disabled, the user must have been created beforehand via a team invitation.
Check SSO Status
The login page can check if SSO is available for a tenant:
GET /api/v1/auth/saml/status/:tenantId
Response: {sso_enabled, enforce_sso, sso_url}