> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/organizations/sso.md).

# Let members sign in to a Duaer organization with their company account

Connect your company sign-in to your Duaer organization so teammates come in with one link and no extra password. Free on every plan.
## One less password, and easier onboarding and offboarding

Your company already signs in through Google Workspace, Microsoft Entra ID, Okta, or another OpenID Connect provider? Connect it to your Duaer organization, and teammates click one sign-in link and come in with their company account.

New hires join the organization on their first sign-in, so you do not send invites one by one. When someone leaves, remove them from the organization and they can no longer get in.

## Before you start: create an app at your identity provider

In your identity provider’s admin console, create an OpenID Connect app and register the Callback URL shown on the Duaer page. Then note three values: the Discovery URL (it usually ends in /.well-known/openid-configuration and must be https), the Client ID, and the Client secret.

## Turn on Duaer organization SSO

1. As the owner or an admin, open Duaer Settings › Organization SSO.
2. Enter the Discovery URL, Client ID, and Client secret, tick Allow sign-in through this provider, and click Save. Duaer checks the Discovery URL first to make sure it works.
3. Copy the Sign-in link for your members and share it in your team chat or on your intranet home page.

The Client secret is never shown again after saving. Leave the field empty when you edit later to keep the saved value.

## Who gets in with a company account

- Existing members: signing in with their company email links to their existing Duaer account. The identity provider must report the email as verified.
- Company emails that never used Duaer: a new account is created and joins the organization as a member.
- People who have a Duaer account but are not in this organization: they are stopped at sign-in and asked to get an invite from the organization’s owner or an admin.
- People removed from the organization: their next company sign-in is refused.

Your identity provider decides who can sign in with a company account. Password sign-in keeps working. Turning organization SSO off or removing it stops the sign-in link, and every member keeps their account.

## Duaer organization SSO versus instance sign-in

Organization SSO covers the members of one organization, is set up by that organization’s owner or an admin, and is free on every plan. Instance-wide OIDC, SAML, and LDAP on a self-hosted Duaer server are separate and set up by the instance admin — refer to [OIDC role provisioning](/user-management/oidc/setup.md) and [LDAP](/user-management/ldap.md).
## Questions

### Does password sign-in still work with Duaer organization SSO?

Yes. Duaer organization SSO adds a sign-in option; members can still sign in with email and password.

### Can someone outside the Duaer organization use the sign-in link?

People who have a Duaer account but are not in the organization are stopped at sign-in and asked for an invite. Company emails that never used Duaer get a new account and join as members, so your identity provider decides who can sign in.

### How is Duaer organization SSO different from instance OIDC or SAML?

Duaer organization SSO covers the members of one organization and is set up by its owner or an admin in Settings. Instance OIDC, SAML, and LDAP are the sign-in methods of a whole self-hosted Duaer server, set up by the instance admin.

