Connect your own identity provider for this team. If the team has a subdomain, the default configuration can be offered automatically to anyone signing in on that subdomain. If there is no subdomain, members use the Login URL for that configuration instead.
Team SSO vs platform SSO
Team SSO configurations live separately from the app-wide SSO path so they are not mixed up with platform providers.
Add a configuration
- Open My Account → Single Sign-On.
- Select New SSO configuration.
- Upload IdP metadata (or complete the fields your IdP requires).
- Copy the generated values into your IdP:
- ACS URL (reply URL) — also used as the SAML audience for this configuration
- Login URL — where members start SSO for this team when not using subdomain auto-offer
- Enable the configuration. Optionally mark it as the one to use on this team’s subdomain.
Subdomain behavior
Subdomains for child teams are managed from Sub-teams.
Who can manage Team SSO
Related
- Sub-teams
- Account Settings (SSO-only login and domain auto-add)
- Platform SSO