---
title: "Enterprise SSO"
description: "Connect your company's identity provider to Shiplight Cloud, configure company SSO, and help employees sign in."
---

# Enterprise SSO

<div class="view-markdown-wrapper">
<ViewMarkdown />
</div>

Enterprise SSO lets employees sign in to Shiplight Cloud with their company identity. Eligible employees can join your organization on their first successful SSO sign-in, with the **member** role.

SSO handles sign-in and admission. To automatically remove organization access when an employee leaves, configure [SCIM Offboarding](/cloud_v2/scim) as well.

## Before you start

- SSO is **not enabled automatically with an Enterprise plan**. Contact your **Shiplight administrator** to enable it for your organization. Your organization owner can then complete setup below.
- An active organization **owner** must start and test the connection.
- Your company's identity administrator needs permission to configure the identity provider (IdP) and verify a company email domain. Domain verification may require access to company DNS.

### WorkOS and Scalekit

Shiplight uses **WorkOS or Scalekit** to connect your organization's identity provider. Shiplight configures the service for your organization; its name appears as **Provider** in Settings and is used for both SSO and SCIM.

Your company IdP is the system where employees authenticate, such as Okta or Microsoft Entra ID. WorkOS or Scalekit provides the setup portal that connects that system to Shiplight. Follow the instructions in the portal opened from Shiplight for the supported SAML or OIDC connection you choose. The available fields and portal appearance depend on your organization's provider.

## Set up company SSO

1. Switch to the organization you want to configure, then open [Settings → Organization](https://app.shiplight.ai/settings/general).
2. In **Enterprise SSO**, select **Set up company SSO**. Shiplight opens your organization's setup portal.
3. Work with your identity administrator to configure the company IdP, assign the appropriate employees to the application, and verify at least one company email domain. Use the connection values and instructions supplied by the portal.
4. Return to Shiplight and select **Refresh status**. Review the connection and verified domains. If setup is incomplete, use **Manage identity provider** to return to the portal.
5. Select **Test connection and finish setup** and complete company authentication. This tests the connection while preserving your owner role and existing sign-in methods.
6. Confirm **Ready for employee sign-in** and **Discovery active** for the verified domain. Copy the **Employee SSO sign-in link** and share it with employees.

Setup links expire quickly. If a portal link expires, open a new one from Settings. Share the employee sign-in link for rollout; keep the administrative setup link private.

After setup, **Manage identity provider** opens the configuration portal, **Refresh status** updates the connection information, and **Test connection** lets you test it again after a configuration change.

## Sign in as an employee

Use either entry point:

- Open [Shiplight sign-in](https://app.shiplight.ai/signin), enter your work email, and choose **Continue with company SSO**.
- Open the organization-specific employee SSO link supplied by your owner.

Complete authentication with your company IdP. Email discovery uses your organization's verified email domain to find the connection. The direct link selects the organization, but access still requires successful authentication and eligibility checks.

### Your first SSO sign-in

For a new company identity, the email domain must be verified for the organization. Shiplight can create the account and ordinary member access during sign-in, without a separate invitation or registration flow. The organization's member limit still applies.

If you already have an active Shiplight account with the same email in the organization's verified domain, Shiplight can link the company identity to that account. Your profile, existing roles, other organization memberships, and existing sign-in methods are preserved. An existing owner remains an owner.

An inactive membership cannot be restored by signing in with SSO again. Ask an owner to [reactivate your membership](/cloud_v2/organization#restoring-access).

## Supported behavior

- Start sign-in from Shiplight or the organization's employee SSO link. IdP-initiated sign-in is not supported.
- Existing email, Google, and GitHub sign-in methods remain available. Mandatory SSO enforcement is not supported.
- Single logout is not supported.
- SSO admission creates ordinary members. Owners manage roles in Shiplight; IdP groups do not map to Shiplight roles.

## Troubleshooting

| What you see                                  | What to check                                                                                                                                                                                            |
| --------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| No Enterprise SSO section                     | Confirm the selected organization and contact your Shiplight administrator to enable SSO. An Enterprise plan alone does not enable it. Once enabled, an organization owner can configure the connection. |
| Your email does not find a company connection | Check the work email domain with your owner. Setup must be ready and the domain must show **Discovery active**. You can also use the organization's employee sign-in link.                               |
| Setup remains incomplete                      | Finish the portal configuration, verify a domain, select **Refresh status**, and complete **Test connection and finish setup**.                                                                          |
| Company authentication fails                  | Ask your identity administrator to check the connection and your application assignment in the IdP.                                                                                                      |
| Account linking fails                         | Check that your account is active and its email matches the company identity in a verified domain. Use your existing Shiplight sign-in method and contact support if the issue persists.                 |
| Membership was removed                        | Ask an owner to reactivate it. Repeated SSO sign-ins do not restore access.                                                                                                                              |
| Organization member limit reached             | Ask an owner to free capacity or arrange a higher limit before retrying.                                                                                                                                 |

## Related

- [SCIM Offboarding](/cloud_v2/scim) — automate employee access removal
- [Organization](/cloud_v2/organization) — members, roles, and settings
- [Billing & Usage](/cloud_v2/billing#enterprise) — Enterprise contracts
