SSO is configured by the organization Owner in Admin Settings → Identity and access.
How setup works
The Identity and access page walks you through three stages:- Verify a domain — prove ownership of your email domain with a DNS TXT record. The Setup SSO button stays disabled until at least one domain is verified.
- Create the connection — a wizard with steps Protocol → SP Metadata → IdP Config (SAML) or Protocol → IdP Config (OIDC).
- Configure provisioning — once the connection is active, choose how users are created and which role and workspaces they get.
Verify your domain
1
Add your email domain
Go to Admin Settings → Identity and access and add your organization’s email domain (for example,
example.com).2
Create the DNS TXT record
Open Verify domain on the domain entry. Add a TXT record at your DNS provider using the Record Name (Host) and Record Value shown.
3
Verify
After the record propagates, click Verify.Success state: the domain shows as verified and the Setup SSO button on the Single sign-on card becomes available.
Create the connection
Click Setup SSO on the Single sign-on card and choose your protocol, then follow the provider-by-provider guide:
After you click Create Connection, use Test on the connection to confirm authentication round-trips before anyone depends on it: a browser tab opens, signs in through your identity provider, and returns to CloudThinker with your name and email.
Enforce SSO
Once the connection is active and tested, you can require it. On the Single sign-on card, turn on Require SSO — users must then authenticate via SSO, and all other login methods are disabled.User provisioning
When the connection is active, the provisioning card offers three modes:
For Just-in-time and SCIM, you also choose the auto-assigned organization role (Viewer, Developer, or Admin — the default is Viewer) and the workspaces new users are added to.
Troubleshooting
Test sign-in fails or shows the wrong name
Test sign-in fails or shows the wrong name
Users can't log in after enforcing SSO
Users can't log in after enforcing SSO
Confirm the CloudThinker app is assigned to the affected users in your identity provider. An Owner with a working SSO session can turn off Require SSO on the Single sign-on card.
A user signs in with a password despite SSO
A user signs in with a password despite SSO
Require SSO applies to users whose email is on a verified domain. Check that the user’s email domain is verified and enforcement is on.
Next steps
SAML Setup
Provider-by-provider SAML configuration steps
OIDC Setup
Provider-by-provider OIDC configuration steps
SCIM Provisioning
Automate user and group sync from your identity provider
Security Overview
MFA, roles and permissions, and audit logs