Single sign-on (SSO)

Let everyone on your email domain sign in with your identity provider. Available on the Growth plan and above.

How it works

You register your identity provider (IdP) once in Settings, SSO. Anyone who enters a work email on that domain at the login page is sent to your IdP and signed in to Glyphex. Google sign-in and email links keep working.

  • OIDC and SAML 2.0 are supported. OIDC is the quickest to set up.
  • You prove you own the email domain with a DNS TXT record before sign-in is enabled.
  • First sign-in creates a Glyphex account for the person. It does not add them to your sites. Invite them from the team page of each site.

Set up in Glyphex

  1. Open Settings, then SSO, and choose Add provider.
  2. Pick OIDC, then enter a name, your email domain (for example acme.com), the issuer URL, client ID and client secret. You can create the app in your IdP first and come back.
  3. Copy the redirect URL Glyphex shows and paste it into your IdP as an allowed redirect (callback) URL.
  4. Add the DNS TXT record shown under the provider, wait a few minutes, then select Verify domain.
  5. Open the login page, choose Sign in with SSO and enter a work email to test.

The redirect URL has the form https://glyphex.io/api/auth/sso/callback/your-provider-id.

Okta

  1. In the Okta admin console go to Applications, Create App Integration, then choose OIDC and Web Application.
  2. Paste the Glyphex redirect URL into Sign-in redirect URIs.
  3. Under Assignments, assign the people or groups who should have access.
  4. Copy the client ID and client secret. The issuer is your Okta domain, for example https://acme.okta.com. If you use a custom authorization server, use https://acme.okta.com/oauth2/default.

Microsoft Entra

  1. In the Entra admin center go to App registrations, then New registration.
  2. Choose Web as the platform and paste the Glyphex redirect URL.
  3. Under Certificates and secrets, create a client secret and copy its value.
  4. Copy the Application (client) ID and your Directory (tenant) ID. The issuer is https://login.microsoftonline.com/TENANT_ID/v2.0.
  5. Under API permissions, make sure openid, email and profile are granted.

Google Workspace

  1. In the Google Cloud console, open APIs and Services, then Credentials, and create an OAuth client ID of type Web application.
  2. Paste the Glyphex redirect URL into Authorized redirect URIs.
  3. On the OAuth consent screen choose the Internal user type so only your Workspace users can sign in.
  4. Copy the client ID and client secret. The issuer is https://accounts.google.com.

SAML

Choose SAML when your IdP does not offer OIDC. In your IdP, set the ACS (reply) URL to the URL Glyphex shows, and the audience (entity ID) to the service provider metadata URL shown next to it. Then paste the IdP sign-in URL, entity ID and signing certificate into Glyphex.

Troubleshooting

Provider domain has not been verified

Sign-in stays off until the DNS TXT record is found. DNS changes can take a few minutes. Check that the host name and value match exactly, then select Verify domain again.

Redirect URI mismatch

Your IdP only accepts redirect URLs it knows. Paste the exact URL from Glyphex, including the provider ID, with no trailing slash.

Email does not match the domain

Glyphex links an SSO sign-in to an existing account only when the email belongs to the verified domain.