---
url: https://flip-chart.ru/knowledge-base/en/sso-and-domains.md
description: >-
  Set up single sign-on (SSO) in a flip space: verify your corporate domain with
  a TXT record, choose the SAML or OpenID Connect protocol and define how new
  users join the space
---

# SSO and domain management

SSO (single sign-on) lets employees sign in to flip through the corporate authentication system, without a separate password. To enable SSO, first verify that the email domain belongs to your company: users whose email is on a verified domain will sign in through your identity provider (IdP)

::: warning Plan limits
The “SSO settings” and “Domain management” sections are available on the Business and Enterprise plans. The space owner and admins can open and configure them
:::

Both sections are located in the space settings: in the left sidebar, click “Space settings” next to the space name

## How to add and verify a domain

1. Open the “Domain management” section and click “Add domain”

2. Enter the domain in the “Domain name” field and click “Add” — it will appear in the “Your domains” list

3. In the “Status” column, click the domain status — the “Technical details” page with the verification code opens

   ![The “Technical details” page with the code for the TXT record](/images/kb/sso-and-domains/1.png)

4. In the domain control panel at your provider, create a new TXT record and paste the copied code into it

5. Wait for the record to be published. Activation can take up to 72 hours: flip checks the record automatically, and the “Check verification” button starts the check manually

The domain status — “Not verified”, “Pending verification” or “Verified” — is shown in the list of domains and on the domain page. A domain can be used for SSO only after it gets the “Verified” status

::: warning Important
Deleting a domain turns off SSO for users with this domain and restricts their access to spaces
:::

## How to enable and configure SSO

1. Open the “SSO settings” section and click “Enable SSO/SAML”

2. In the “Protocol” field, select the protocol your authentication system uses — OpenID Connect or SAML 2.0 — and fill in the connection parameters

3. Click “Test SSO configuration” and make sure the test passes

   ![The “SSO settings” section with the connection parameters](/images/kb/sso-and-domains/2.png)

4. Check the list of domains: it shows only verified domains. Users from these domains will sign in with SSO

5. Choose how new users join the space:

   * “Automatically” — all users who sign in via SSO are added to the space. In the “Default team for new users” field, select the team they will join
   * “By invitation” — new users are added to the space only by admin invitation

6. Click “Save”

To turn SSO off, switch off the “Single Sign-On” toggle at the top of the section and confirm with the “Turn off” button

## How users sign in with SSO

On the login page, the user chooses to sign in with SSO and enters their email address. flip redirects them to the sign-in page of your identity provider and, after a successful sign-in, brings them back to the space

If the space doesn't have enough licenses for a new user, they will see the “Not enough licenses” message when signing in. If the “By invitation” option is selected and the user has no invitation, they will see the “Access to the space is restricted” message

## Detailed instructions

Step-by-step instructions with screenshots are published in the developer documentation:

* [SSO setup](https://flip-chart.ru/developers/en/cloud/auth/sso)
* [Domain verification](https://flip-chart.ru/developers/en/cloud/auth/domain)

For the roles that have access to these sections, see [Space member roles](/en/space-roles). For the plan features, see [Business plan overview](/en/tariff-business)
