Skip to content
Plain Help Center home
Plain Help Center home

Single sign-on (SSO)

You can configure SSO within Plain in Settings -> SSO.

We use our WorkOS to power our authentication, SSO and Directory sync functionality. You can read their documentation on how to integrate your specific authentication provider: https://workos.com/docs/integrations

SSO and Directory sync are only available to our Frontier plans

Single sign-on (SSO)

Single Sign-On (SSO) makes it easy and secure for your team to access Plain using the same identity provider (IdP) you use for the rest of your company tools such as Okta, Azure AD, Google Workspace, or OneLogin.

After verifying you own the domain (see below), you can configure SSO from the Settings -> SSO -> SSO configuration section.

Once SSO is enabled for your workspace, it will become the required authentication mechanism for all users in your workspace. If need to allow other authentication methods, please get in touch with us

Domain Verification

This is a security requirement. Some authentication providers do not enforce email verification, meaning a malicious individual could attempt to claim an email such as john@acme.com without actually owning that address.

You can prove ownership of your domain by going to Settings -> SSO -> Domain verification. This will redirect you to WorkOS where you will complete the verification process.

Share SSO connection amongst different workspaces

If you use multiple Plain workspaces and would like to centralise the SSO connection management, get in touch with us and we will work with you to configure it.

Role assignment

If a user is provisioned via SSO they will:

  • Be assigned the None role

  • Appear in the Others tab under Settings -> Members -> Other tab

  • Not incur additional seat charges

You can manually change their role at any time from within Plain (Settings -> Members) or the WorkOS admin dashboard (Settings -> SSO)