Single sign-on lets your team sign in to SimpleKPI with your existing identity provider — Microsoft Entra ID, Okta, Google Workspace, Auth0, or any standard OIDC provider. It means one less password to manage and central control over who has access. Only account owners and admins can configure it.
Configure your identity provider
- Go to Settings → SSO.
- Choose your Provider from the list.
- Enter the Authority (issuer URL), your Client ID, and Client secret. The metadata URL is optional — leave it blank to use the standard discovery path.
- Copy the Redirect URI shown on the page and register it in your identity provider.
- Click Test connection to confirm the details are correct, then Save.
Verify your email domains
Users whose email is on a verified domain are routed to your identity provider at sign-in. Verifying a domain proves you own it.
- Under Email domains, type a domain (e.g. acme.com) and click Add domain.
- Add the DNS TXT record shown — the host and value are displayed for you.
- Once the record is live, click Verify. The domain shows a green Verified badge when it's confirmed.
Turn it on
Under Activation, tick Enable SSO for this account and save. Once at least one person has signed in successfully via SSO, you can also tick Require SSO to make it the only sign-in method for members.
The account owner always keeps email-code sign-in as a fallback, even with Require SSO on — so a misconfigured provider can never lock you out. Run Test connection and complete one real SSO login before requiring it.