Skip to content

Enterprise SSO

Enterprise SSO lets employees sign in to Shiplight Cloud with their company identity. Eligible employees can join your organization on their first successful SSO sign-in, with the member role.

SSO handles sign-in and admission. To automatically remove organization access when an employee leaves, configure SCIM Offboarding as well.

Before you start

  • SSO is not enabled automatically with an Enterprise plan. Contact your Shiplight administrator to enable it for your organization. Your organization owner can then complete setup below.
  • An active organization owner must start and test the connection.
  • Your company's identity administrator needs permission to configure the identity provider (IdP) and verify a company email domain. Domain verification may require access to company DNS.

WorkOS and Scalekit

Shiplight uses WorkOS or Scalekit to connect your organization's identity provider. Shiplight configures the service for your organization; its name appears as Provider in Settings and is used for both SSO and SCIM.

Your company IdP is the system where employees authenticate, such as Okta or Microsoft Entra ID. WorkOS or Scalekit provides the setup portal that connects that system to Shiplight. Follow the instructions in the portal opened from Shiplight for the supported SAML or OIDC connection you choose. The available fields and portal appearance depend on your organization's provider.

Set up company SSO

  1. Switch to the organization you want to configure, then open Settings → Organization.
  2. In Enterprise SSO, select Set up company SSO. Shiplight opens your organization's setup portal.
  3. Work with your identity administrator to configure the company IdP, assign the appropriate employees to the application, and verify at least one company email domain. Use the connection values and instructions supplied by the portal.
  4. Return to Shiplight and select Refresh status. Review the connection and verified domains. If setup is incomplete, use Manage identity provider to return to the portal.
  5. Select Test connection and finish setup and complete company authentication. This tests the connection while preserving your owner role and existing sign-in methods.
  6. Confirm Ready for employee sign-in and Discovery active for the verified domain. Copy the Employee SSO sign-in link and share it with employees.

Setup links expire quickly. If a portal link expires, open a new one from Settings. Share the employee sign-in link for rollout; keep the administrative setup link private.

After setup, Manage identity provider opens the configuration portal, Refresh status updates the connection information, and Test connection lets you test it again after a configuration change.

Sign in as an employee

Use either entry point:

  • Open Shiplight sign-in, enter your work email, and choose Continue with company SSO.
  • Open the organization-specific employee SSO link supplied by your owner.

Complete authentication with your company IdP. Email discovery uses your organization's verified email domain to find the connection. The direct link selects the organization, but access still requires successful authentication and eligibility checks.

Your first SSO sign-in

For a new company identity, the email domain must be verified for the organization. Shiplight can create the account and ordinary member access during sign-in, without a separate invitation or registration flow. The organization's member limit still applies.

If you already have an active Shiplight account with the same email in the organization's verified domain, Shiplight can link the company identity to that account. Your profile, existing roles, other organization memberships, and existing sign-in methods are preserved. An existing owner remains an owner.

An inactive membership cannot be restored by signing in with SSO again. Ask an owner to reactivate your membership.

Supported behavior

  • Start sign-in from Shiplight or the organization's employee SSO link. IdP-initiated sign-in is not supported.
  • Existing email, Google, and GitHub sign-in methods remain available. Mandatory SSO enforcement is not supported.
  • Single logout is not supported.
  • SSO admission creates ordinary members. Owners manage roles in Shiplight; IdP groups do not map to Shiplight roles.

Troubleshooting

What you seeWhat to check
No Enterprise SSO sectionConfirm the selected organization and contact your Shiplight administrator to enable SSO. An Enterprise plan alone does not enable it. Once enabled, an organization owner can configure the connection.
Your email does not find a company connectionCheck the work email domain with your owner. Setup must be ready and the domain must show Discovery active. You can also use the organization's employee sign-in link.
Setup remains incompleteFinish the portal configuration, verify a domain, select Refresh status, and complete Test connection and finish setup.
Company authentication failsAsk your identity administrator to check the connection and your application assignment in the IdP.
Account linking failsCheck that your account is active and its email matches the company identity in a verified domain. Use your existing Shiplight sign-in method and contact support if the issue persists.
Membership was removedAsk an owner to reactivate it. Repeated SSO sign-ins do not restore access.
Organization member limit reachedAsk an owner to free capacity or arrange a higher limit before retrying.

Released under the MIT License.