How to set up single sign-on (SSO)
You configure SSO in Settings, then SSO. SSO is available on the Frontier plan.
SSO lets your team sign in to Plain with the identity provider you use for the rest of your company tools, such as Okta, Azure AD, Google Workspace or OneLogin. Plain uses WorkOS to power SSO and directory sync, so some steps send you to its dashboard to finish. For steps specific to your identity provider, see the integration guides.
Once SSO is enabled, it becomes the required login method for everyone in your workspace. If you need to allow other login methods as well, contact Plain support.
Verify your domain
You must prove you own your email domain before you can enable SSO. Some identity providers do not enforce email verification, so without this step someone could try to claim an address such as john@acme.com without owning it.
Go to Settings, then SSO, then Domain verification. Plain sends you to the vendor dashboard to complete the verification.
Configure SSO
After your domain is verified, go to Settings, then SSO, then SSO configuration, and connect your identity provider.
Roles for users provisioned through SSO
When a user is provisioned through SSO, Plain:
- Assigns them the None role.
- Lists them in the Others tab, under Settings, then Members.
- Does not charge for an additional seat.
You can change their role at any time in Settings, then Members, or in the admin dashboard linked from Settings, then SSO.
Multiple workspaces
If you have several Plain workspaces and want one SSO connection for all of them, see How to set up SSO and SCIM across multiple workspaces.