Skip to content
All guides

Single sign-on

On the Enterprise plan, your team signs in through your identity provider. Works with Okta, Microsoft Entra, Google Workspace or any OIDC-compliant IdP.

  • Create an OIDC application in your identity provider and allow the redirect URI shown in Settings under Single sign-on.
  • Back in crmSpace, enter the issuer URL, your email domain, and the application's client ID and secret. The discovery endpoint is derived from the issuer; you can override it if your IdP uses a non-standard path.
  • From then on, anyone at your domain picks "Use single sign-on" at sign-in, enters their work email, and is sent to your IdP. Your IdP's own policies, including MFA, apply.
  • SSO signs people in; workspace membership still comes from an invite. Invite a member by their work email first, then they sign in through SSO.
  • Removing SSO in Settings takes effect immediately and members fall back to password sign-in. Accounts and access are unchanged.
  • Want help wiring up a specific IdP? Contact us and we will set it up with you. The connector speaks OIDC; we do not offer SAML today.