Auth and identity · Concept

Single sign-on (SSO)

One sign-in that works across many apps, so staff log in once with their company account and get into every tool their employer has connected.

Basics · updated

How it works

With SSO, an app stops checking passwords itself and trusts an identity provider (IdP) such as Okta, Microsoft Entra ID or Google Workspace. The app sends the user to the IdP, the IdP signs them in with its own password rules, 2FA and device checks, and returns a signed statement of who they are. Two standards carry that statement: SAML 2.0, an older XML format still common in enterprises, and OpenID Connect, its modern JSON and JWT based counterpart.

For a company, SSO means one place to enforce security and one switch that removes a leaver's access everywhere, often paired with SCIM, which creates and deletes accounts in each app automatically. For a software vendor it is usually the feature that unlocks business customers, which is why many products reserve it for their top plan, a habit nicknamed the 'SSO tax'. 'Sign in with Google' on a consumer site is the same idea on a smaller scale.

More in Auth and identity

Basics

All 17 Auth and identity terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.