Set up single sign-on
Verify a domain, connect SAML or OIDC, and choose whether new users are created on first sign-in.
Joring supports SAML 2.0 and OIDC. Both are vendor-agnostic, so any identity provider that speaks either protocol works — Okta, Entra ID, Google Workspace, Authentik, and others.
SSO is an Enterprise feature. Setup runs in three stages, in this order: domain, connection, policy.
Verify your domain
In Settings → Single Sign-On, add the email domain your people sign in with, then publish the DNS record Joring gives you.
Verification is what stops someone else from claiming your domain and capturing your sign-ins, so a connection cannot go live without it.
Create the connection
Pick SAML or OIDC.
Upload your IdP's metadata XML or paste its URL. Joring parses it and shows you what it read — entity ID, sign-in URL, certificate — before anything is saved. Check that screen rather than clicking through it: a wrong entity ID produces a failure at sign-in time that looks like a certificate problem.
Joring's own service-provider metadata is on the same page, for the side of the configuration you do in your IdP.
Test the connection before activating it. The test runs a real authentication round-trip and reports what came back.
Choose your sign-in policy
Two settings decide what happens when someone from a verified domain signs in and has no Joring account:
- Just-in-time provisioning creates the account on first successful sign-in. Anyone your IdP lets through gets in.
- Invite only requires an existing invite. Your IdP authenticates them; Joring still decides who is a member.
Turn JIT on if your IdP already governs who should have access. Leave it off if Joring access is narrower than IdP access — for example, a paid pilot with one department inside a company where everyone can authenticate.
Keep one non-SSO administrator
If the IdP connection breaks, an SSO-only team can lock itself out of the settings needed to fix it. Keep at least one Owner or Admin who can sign in another way.
Automate account creation and deprovisioning from your directory.