enterprise
SSO
Sign in with your identity provider (Enterprise).
SSO (Enterprise) lets an organization sign in through its own identity provider over OIDC instead of managing passwords on the platform.
Configure#
From the organization's SSO settings:
- Set the issuer URL of your provider (e.g. Google, Entra ID, Keycloak) — the platform discovers the provider endpoints from it.
- Paste the client ID and client secret issued for ZenSailor in your provider.
- Restrict to allowed domains — only members whose email matches sign in through SSO.
- Choose the default role assigned to first-time SSO members.
Each organization gets a dedicated sign-in URL, so a member lands on their own organization's provider, not a shared prompt.
Switching#
Existing members keep their email identity when SSO is enabled; the first SSO sign-in for a matching domain binds the provider account to the organization. Members can continue using passwords where their organization allows it, or the organization can enforce SSO for the domains it manages.