---
title: "SSO and Directory Sync"
description: "Set up single sign-on for an API Platform organization: verify your domain, connect your identity provider, and understand how people sign in and join."
icon: "shield-check"
---

Single sign-on (SSO) lets the people in your company sign in to QuiverAI with the accounts your company already manages, through your identity provider (IdP), such as Okta, Microsoft Entra ID, or Google Workspace. QuiverAI connects to your IdP with SAML or OpenID Connect (OIDC), the two standard protocols for this. This page is for the Owner or Admin who sets it up and for the IT administrator who configures the IdP.

SSO is offered to organizations on an enterprise agreement. Directory Sync, which keeps members and roles in step with your company directory, is coming soon.

## Before you start

- You must be an Owner or Admin of the organization in the [API Platform](https://platform.quiver.ai).
- QuiverAI must turn SSO on for your organization. Contact sales or your account team. Until it is on, the **Single sign-on** section does not appear on the Organization page.
- You need access to your IdP and to your domain's DNS records, or an IT administrator who has both.

## What turning on SSO changes

Once the connection is active, everyone with an email address on your verified domains must sign in with SSO. This applies to both the API Platform and the App at app.quiver.ai, and it applies to every such person whether or not they are already a member of your organization.

- Their other sign-in methods, such as Google or an email code, stop working for those addresses.
- There is no separate switch to enforce SSO or to relax it later. An active connection enforces it.
- People you invite with an email address outside your verified domains are not affected and keep signing in as they do today.
- Existing API keys keep working. Keys belong to projects, not to people, so activating SSO does not revoke any.

Because of this, verify your domain, then configure and test the connection, before you announce SSO to employees.

## Set up the connection

1. **Open the Single sign-on section**

    Go to the [Organization page](https://platform.quiver.ai/organization) and
    find **Single sign-on**. It has a **Connection** row and a **Domains** row.

2. **Verify your domain**

    Select **Verify domain**. Until a connection is active, a confirmation
    dialog explains that SSO will apply to everyone on your verified domains;
    choose **Continue to setup**. In the WorkOS Admin Portal that opens, add the
    DNS TXT record it shows to your domain. WorkOS is the service QuiverAI uses
    to run SSO, and the Admin Portal is a hosted page built for IT
    administrators. A verified domain is one you have proven you own. Public
    email domains such as gmail.com cannot be verified.

3. **Configure SSO**

    Select **Configure SSO** and connect your IdP in the Admin Portal, which
    gives instructions for each supported IdP. See the [WorkOS Admin Portal
    documentation](https://workos.com/docs/admin-portal) if your IT
    administrator needs more detail.

4. **Sign in with SSO once**

    The connection is not complete until someone on a verified domain signs in
    through it successfully. Do this yourself, with your work email, as a test.

The Admin Portal link is generated when you ask for it and expires after five minutes. If it expires, or you hand the task to your IT administrator, open it again from the Organization page. QuiverAI never emails it.

### Status

The **Single sign-on** section shows whether setup is not started, in progress or complete, and a badge for the connection and for each domain. Status is read live when the page loads. Setup shows as complete only after the first successful SSO sign-in.

## How people sign in

In the API Platform, people enter their work email address and choose **Continue with email**; an address on a verified domain goes straight to your IdP. In the App, they choose **Send code** and enter the code they receive, and are then sent to your IdP. There is no separate SSO button. Starting from the QuiverAI tile in your IdP dashboard works too.

## Joining and roles

When someone on a verified domain signs in with SSO and is not yet a member, QuiverAI adds them automatically. This is called just-in-time (JIT) provisioning.

- They join as a Developer with access to the Default Project.
- SSO never makes anyone an Owner.
- An Admin can change their role and project access afterward on the Organization page.
- Invites still work. If someone joined automatically and then opens an invite, the invited role and project access apply, as long as nobody has changed their role or access since they joined. An invite to Viewer leaves their role and access unchanged while they still hold API keys; an Admin changes it once the keys are reassigned or revoked.

People who were removed from the organization, or who left it, are not added back by SSO. They see "You signed in with single sign-on, but you don't have access to this organization yet. Ask an admin of the organization to invite you." An Owner or Admin can bring them back by selecting **Restore** on the **Removed** tab of **Members** on the Organization page, or by sending a new invite.

By default, people with a verified-domain address can't create separate organizations, so company usage stays in yours. Personal organizations they created before verification stay as they are; QuiverAI never moves or deletes them. To bring that work into your organization, invite the person, create new API keys in your organization's projects, and have them delete their personal organization when it is no longer needed.

### Guests and contractors

Invite people whose email is outside your verified domains. They sign in with Google or an email code, as before.

### Removing access

Disabling someone in your IdP stops their next SSO sign-in. It does not end a session they already have open. Until Directory Sync is available, to remove access immediately, also remove them from the organization on the Organization page. Their API keys are not revoked either way, because keys belong to projects.

## Directory Sync

:::warning[Coming soon]
Directory Sync is not available yet. This section describes the planned behavior and may change. Nothing here can be configured today.
:::

Directory Sync connects your IdP's directory, so members and roles follow your company's groups instead of manual invites and edits.

### Connect a directory

Planned: Owners and Admins connect a directory from the same **Single sign-on** section, using the Admin Portal.

### Roles from groups

Planned: directory groups map to Admin, Developer, or Viewer. The directory never grants or changes Owner. A group that maps to any other role is not applied, and QuiverAI is alerted.

### Managed members

Planned: while a directory is active, members it manages are labelled and their role and removal are locked in QuiverAI. Project access stays editable. Members who are not in the directory are labelled so you can review them.

### Removal

Planned: removing someone in the directory removes their access and ends their sessions. API keys they created are reassigned to another holder, not revoked. The directory cannot remove the last Owner.

### Joining and disconnecting

Planned: automatic JIT joining stops while a directory is active. If you disconnect the directory, members keep their access, become editable again, and JIT joining returns.

## Troubleshooting

**"Single sign-on isn't set up for this email domain. Use another sign-in method."** The address is not on a verified domain with an active connection. Check the domain and connection badges on the Organization page.

**"Your organization isn't available for single sign-on right now. Contact your administrator."** The organization's SSO setup has a problem. An Owner or Admin should check the Organization page and the IdP configuration.

**One person cannot sign in.** Their IT administrator should check that the person is assigned to the app in the IdP and that their IdP email is on a verified domain.

**Everyone is locked out because the IdP is broken.** An Owner or Admin contacts QuiverAI support from a channel QuiverAI already knows for your organization, such as your account team, since company email may be affected too. Support can deactivate the connection, which restores the other sign-in methods. Then repair the connection in the Admin Portal and sign in with SSO again.

**[Open Organization](https://platform.quiver.ai/organization)**

Verify your domain, configure SSO, and manage members and removed members.
