Changelog · back to all
Single sign-on is available to every organization
Your organization can now set up single sign-on. Members sign in through your own identity provider instead of keeping a separate Bird password, and you decide whether that is optional or required.
Setup runs from the Single sign-on page on your organization. Verify an email domain by DNS record, configure a SAML 2.0 or OpenID Connect connection, run a test sign-in against your provider, and activate it. A connection can grant new members a default role on their first sign-in, so someone arriving from your directory lands with the access you intended rather than none.
Turning on the requirement takes effect immediately, on every request. A member whose current session did not come through your identity provider signs in again through it, so plan the change around your team's day. Organization Owners keep access with their Bird password, which is what stops a misconfigured connection locking everyone out.
Credential rotation, suspend and resume, and deletion are all in the surface, and every one of those actions is recorded in your audit log.
The field names differ in each provider, and each has one setting that refuses every sign-in when it is wrong, so start from the guide for yours:
SSO and provisioning covers the parts that are the same whichever provider you use.
Related resources
Continue with the documentation, guides and examples for this topic. Resources are in English.