> For the complete documentation index, see [llms.txt](https://docs.spreo.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.spreo.io/management/single-sign-on.md).

# Single Sign-On

Set up SAML Single Sign-On for your organization.

{% hint style="info" %}
SSO is only available for teams on the Business or Enterprise plans
{% endhint %}

Spreo supports Single Sign-On (SSO) via the SAML protocol. You will need the SAML Endpoint, Issuer and Certificate values from your Identity Provider in order to configure Spreo SSO.

### Set up SSO

Owners and Admins set up SSO in Spreo under **Manage**, then **Single Sign-On**.

1. Choose your Identity Provider: Google, Okta, Azure, or Other for any SAML 2.0 provider.
2. Follow the steps on screen. Spreo shows the two values to copy into your Identity Provider: the single sign-on (ACS) URL, in the form `https://spreo.io/login/saml2?p=YOUR-ACCOUNT-ID`, and the Entity ID, in the form `https://spreo.io/YOUR-ACCOUNT-ID`.
3. Copy the Entry Point (SSO URL), Issuer and Certificate from your Identity Provider into Spreo, and save.
4. In your Identity Provider, map three attributes: `firstName`, `lastName` and `email`.
5. Give the right users or groups access to Spreo in your Identity Provider, then test a sign-in.

### Email domains

You will also need to configure the email domains you would like to map for this SSO configuration. When signing-in, users presenting an email address from one of these domains will be redirected to your Identity Provider for authentication.

Domains are configured by our support team. Please drop us an email at <contact@spreo.io> or speak to us on Intercom to set these up.

### What changes once SSO is on

* Every member who is not a guest must sign in through your Identity Provider.
* The first time someone signs in through SSO, their Spreo user is created and they join the Organization as a Member, if a seat is free.
* **Max Session Duration (Hours)** is optional. It sets how long before each user has to sign in again through your Identity Provider.
* **Whitelist** is optional. It is a list of email addresses that are allowed to bypass SSO.
* Service provider metadata is available at `https://spreo.io/login/saml2/metadata?p=YOUR-ACCOUNT-ID`.

<figure><img src="https://2875185778-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwEhLPSRTDuhd61395hZu%2Fuploads%2FPJwj7r8KjeHLg33vZqmN%2Fmanage-SSO.png?alt=media&#x26;token=726a6e8c-d9da-4073-9366-964d7bb6d869" alt=""><figcaption></figcaption></figure>

### Legacy Access

For teams who are still using our previous SSO setup process, please refer to the guides below, or contact us if you need any help.

{% content-ref url="/pages/-Mkkxn6ZwfWLiHDSMPFh" %}
[Azure Integration](/management/azure.md)
{% endcontent-ref %}

{% content-ref url="/pages/uo0MBK45MEsLOhhN7hZI" %}
[Google Integration](/management/google-sso.md)
{% endcontent-ref %}

{% content-ref url="/pages/-Mi5zZMAJoxn6sC0EOug" %}
[Okta Integration](/management/okta-sso.md)
{% endcontent-ref %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.spreo.io/management/single-sign-on.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
