> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vainona.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on

> Your people sign in to the dashboard through your identity provider, SAML or OIDC. Scale plan.

On Scale, an owner connects your identity provider, such as Okta, Microsoft Entra ID or Google Workspace, over SAML or OIDC. People from your verified domain then sign in to the dashboard through it, and someone signing in for the first time joins your organization.

SSO is for the dashboard. API keys are unchanged: they are created on the Keys page and scoped as before.

## Set it up

An owner sets up SSO in the dashboard, under **Settings → Single sign-on**. Every member can see what is set up; only owners change it, since it decides who can sign in.

1. **Set up SSO** opens the Admin Portal, where you pick your identity provider and follow its steps: an app to create on your side, and its metadata or client details to paste back. The portal says what your provider needs.
2. **Verify a domain** opens the portal to verify the domain your people's email addresses are on, such as `acme.com`, with a DNS record.
3. When you're done, the portal returns you to Settings, which lists the connection and the domain with their status. Once the connection is `active` and the domain `verified`, people from that domain sign in through your provider.

The first time an owner opens the portal it's recorded in your audit log as `org.sso`.

## Who can sign in, and with what role

* **Someone from your verified domain** who signs in through your provider and isn't a member yet joins your organization as **read\_only**, the least privileged role: they can see everything and change nothing. An owner gives them another role on the **Members** page. The join is in your audit log as `member.put`, by `system:sso`.
* **A member** keeps the role an owner gave them.
* **Removing someone** starts in your identity provider: once it stops letting them in, they can't sign in through it. Remove them on the Members page as well, which ends their membership.

## After a downgrade

SSO is a Scale feature. A downgrade takes effect on the 1st of a month at least 30 days after you ask ([changing plan](/pricing#changing-plan)); until then nothing changes. From its date:

* **The connection stays.** Your members keep signing in through your provider.
* **Nobody new joins through it**, and owners can't open the Admin Portal to change it.
* **Upgrading again** restores all of it at once. Nothing has to be set up again.
