Skip to main content

Enterprise Single Sign-On

Available on Advanced and Enterprise tiers Connect Zephior to your organization’s identity provider so team members can sign in with their corporate credentials. Image

Supported Protocols

OpenID Connect (OIDC)

Modern standard supported by most identity providers. Recommended for new setups.

SAML 2.0

Enterprise standard compatible with legacy systems and corporate IdPs.

Supported Identity Providers

ProviderProtocol
OktaOIDC / SAML
Microsoft Entra ID (Azure AD)OIDC / SAML
Google WorkspaceOIDC
PingFederateSAML
ADFSSAML
OneLoginOIDC / SAML
JumpCloudOIDC / SAML
Any OIDC or SAML 2.0 compliant identity provider works with Zephior.

Setting Up SSO

1

Verify Your Domain

Add a DNS TXT record to prove domain ownership.
  1. Go to SettingsSSO
  2. Enter your domain (e.g., yourcompany.com)
  3. Add the provided TXT record to your DNS
  4. Click Verify Domain
2

Configure Your Identity Provider

For OIDC: Obtain Client ID, Client Secret, and Discovery URL from your IdP.For SAML: Obtain Metadata URL, Entity ID, and X.509 Certificate.
3

Connect to Zephior

  1. Select your protocol (OIDC or SAML)
  2. Enter your IdP credentials
  3. Click Save Connection
4

Test and Enable

  1. Click Test Connection to verify
  2. Toggle Enable SSO for Organization

How SSO Login Works

  1. User enters their email at login
  2. Zephior detects the SSO-enabled domain
  3. User clicks Continue with SSO
  4. User authenticates via your identity provider
  5. User is signed into Zephior

Auto-Provisioning

SettingBehavior
EnabledUsers automatically join on first SSO login
DisabledUsers must be invited before accessing Zephior

SSO Features

FeatureDescription
Multi-Domain SupportAdd multiple domains to one SSO connection
MFA PassthroughYour IdP’s MFA policies are respected
JIT ProvisioningNew users can self-provision via SSO

Managing SSO

Update Configuration

  1. Go to SettingsSSO
  2. Click Edit Connection
  3. Update credentials and test

Disable SSO

  1. Toggle off Enable SSO for Organization
  2. Users will need to set Zephior passwords
Disabling SSO requires all users to create new passwords.

Troubleshooting

Verify the email domain matches your configured domains in SettingsSSO.
Check that Client ID/Secret are correct and callback URLs are allowed in your IdP.
DNS changes can take up to 48 hours. Verify the TXT record is correctly added.