> ## Documentation Index
> Fetch the complete documentation index at: https://www.wirebase.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on (SSO)

> Let members sign in through your identity provider with OIDC or SAML 2.0.

## Overview

With SSO, members sign in to Wirebase through your identity provider (IdP), such as Okta, Microsoft Entra ID or Google Workspace. Users whose email domain matches an SSO provider are signed in through it.

| Protocol | Plan |
| - | - |
| **OIDC** (OpenID Connect) | Team and Enterprise |
| **SAML 2.0** | Enterprise |

Configure SSO in **Admin → Settings → SSO**.

## Add an OIDC provider

<Steps>
  <Step title="Create an app in your IdP">
    Create an OIDC web application. Set its redirect (callback) URL to:

    ```text theme={null}
    https://www.wirebase.com/api/auth/sso/callback/<provider-id>
    ```

    Replace `<provider-id>` with the ID you'll choose in the next step.
  </Step>

  <Step title="Add the provider in Wirebase">
    Click **Add OIDC** and fill in:

    | Field | Example |
    | - | - |
    | **Provider ID** | `okta-prod`: a unique slug for this provider |
    | **Issuer URL** | `https://accounts.google.com` |
    | **Client ID** / **Client Secret** | From your IdP app |
    | **Email Domain** | `yourcompany.com`: users with this email domain use this provider |
  </Step>
</Steps>

## Add a SAML provider

<Steps>
  <Step title="Start in Wirebase">
    Click **Add SAML** and enter a **Provider ID**. The dialog then shows the values to configure in your IdP:

    | IdP setting | Value |
    | - | - |
    | **SP Entity ID / Audience URI** | Shown in the dialog |
    | **ACS / Reply URL / Callback URL** | `https://www.wirebase.com/api/auth/sso/saml2/callback/<provider-id>` |
    | **SP Metadata URL** | `https://www.wirebase.com/api/auth/sso/saml2/sp/metadata?providerId=<provider-id>` |
  </Step>

  <Step title="Create the SAML app in your IdP">
    Use the values above, then download your IdP's metadata XML.
  </Step>

  <Step title="Finish in Wirebase">
    Paste the IdP metadata, set the **Email Domain**, and save.
  </Step>
</Steps>

<Tip>
  If you serve Wirebase on a [custom domain](/docs/admin-guide/security/custom-domain), use the URLs exactly as the dialog shows them; they reflect the domain you're configuring from.
</Tip>

## How members sign in

On the sign-in page, members click **Sign in with SSO** and enter their work email. Wirebase sends them to your IdP and, after they authenticate, signs them in to your organization. New users from your domain are added to your organization automatically.

## Remove a provider

Delete it from the providers list. Creating and deleting SSO providers is recorded in the [audit log](/docs/admin-guide/usage/audit-logs).

## Related

* [SCIM](/docs/admin-guide/security/scim): create and deactivate users automatically.
* [Custom domain](/docs/admin-guide/security/custom-domain): require SSO on your own domain.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.