# Single sign-on (SSO) with SAML or OIDC

> Set up single sign-on for your analytics workspace with SAML 2.0 or OpenID Connect: IdP values, email domains, just-in-time provisioning and enforcing SSO.

SSO is available on the **Business** plan. Members sign in through your
identity provider (IdP), so you control access centrally.

## Values for your identity provider

Replace `ws_…` with your workspace id (Workspace settings → Overview).

### SAML 2.0

| Setting | Value |
|---|---|
| ACS (reply / single sign-on) URL | `https://privatusanalytics.com/users/auth/saml/callback` |
| SP entity ID (audience) | `https://privatusanalytics.com/users/auth/saml/metadata?workspace=ws_…` |
| Name ID format | `emailAddress` |
| Name ID value | The user's email address |
| Attributes (optional) | `name` or `displayName` for the member's name |

From the IdP, you'll need its **SSO URL**, **entity ID (issuer)** and
**X.509 signing certificate**, or its metadata XML to import.

### OpenID Connect

| Setting | Value |
|---|---|
| Redirect (callback) URI | `https://privatusanalytics.com/users/auth/openid_connect/callback` |
| Scopes | `openid email profile` |
| Flow | Authorization code with PKCE |

From the IdP, you'll need the **issuer URL** (we use its discovery
document), a **client id** and a **client secret**.

## Set up

1. **Workspace settings → SSO.** Choose SAML or OIDC and enter
   the IdP's values.
2. List your **email domains**. Only people with those domains can sign in
   through SSO.
3. Choose **just-in-time provisioning** and the **default role** for new
   members (any role except Owner).
4. **Test**: sign in through the IdP in a private window. A successful
   test marks the configuration as tested. Nothing changes for other
   members.
5. **Activate.** Members can now use **Log in with SSO** (enter your email
   or domain).
6. Optional: **Enforce SSO**, so members of this workspace must sign in
   through the IdP. Keep one owner with another sign-in method as a break-glass
   account.

## Signing in

On the login page choose **Log in with SSO** and enter your work email. You
are sent to your IdP and back. Start sign-in from Privatus Analytics (SP-initiated).
Tiles in your IdP's app dashboard should link to the Privatus Analytics SSO login
page.

## Guides

[Okta](/docs/teams/sso-okta) · [Microsoft Entra ID](/docs/teams/sso-entra-id) ·
[Google Workspace](/docs/teams/sso-google-workspace) ·
[JumpCloud](/docs/teams/sso-jumpcloud). To create and remove members
automatically, add [SCIM](/docs/teams/scim).
