Set up single sign-on (SSO)
Connect your identity provider so your team signs in to Clav with your corporate credentials — and, if you choose, make it the only way in.
What single sign-on gives you
With SSO, Clav stops being a separate account your team has to manage. Access follows your identity provider: your password policy, your multi-factor rules and your conditional access apply, and revoking someone there removes their way into Clav.
One set of credentials
Your team signs in with the corporate account they already use every day.
Verified domain
A provider only becomes active once you prove, via DNS, that the email domain is yours.
Optional enforcement
Force SSO makes your identity provider the only accepted way to reach your data.
Before you start
Supported protocols
Clav supports SAML 2.0 and OpenID Connect. No provider-specific extensions are required, so any conformant identity provider will work.
Connect your identity provider
- 1
Create the application in your identity provider
In your IdP, create an application for Clav and copy the values it gives you. For OIDC you need the issuer URL, the client ID, the client secret and the discovery endpoint. For SAML you need the issuer (entity ID), the sign-on URL and the signing certificate.
- 2
Open your organization security settings
In the platform, go to your organization's settings and open the Security tab. Single sign-on is configured here, alongside the two-factor and enforcement policies.
- 3
Add the provider
Click Add provider. Give it a short Provider ID that identifies your IdP (for example "okta"), choose the Provider type — OIDC or SAML — and fill in the Issuer and the Email domain your members sign in with. Then complete the type-specific fields: Client ID, Client secret and Discovery endpoint for OIDC; SSO URL and Certificate for SAML.
- 4
Verify the email domain
Click Verify domain. Clav shows a DNS TXT record name and value. Publish that record on your domain, wait for DNS to propagate, then click check. The provider stays inactive until this succeeds — this is what proves the domain is yours.
- 5
Test the sign-in
Sign out and use Sign in with SSO with an address on the verified domain. Confirm that at least one administrator can get in through the identity provider before moving to the final step.
- 6
Optional: enforce SSO for everyone
Once you have confirmed SSO works, turn on Force SSO to make it the only way in. Email and password sign-in and Google sign-in are then rejected for every member of your organization.
Proving the domain is yours
When you click Verify domain, Clav generates a DNS TXT record name beginning with the clav-verification prefix, together with a unique value. Publish it on the email domain you registered, then return to the dialog and run the check.
Until that check succeeds, the provider does not authenticate anyone. This is a deliberate safeguard: it stops a third party from registering a provider that claims your domain and intercepting your members' sign-ins.
DNS propagation
TXT records can take from a few minutes to a few hours to propagate. If the check fails at first, wait and try again — you do not need to re-create the provider.
Making SSO the only way in
Force SSO is an organization-level policy. With it enabled, every attempt to sign in with an email and password or with Google is rejected for members of your organization, no matter how the request reaches Clav.
Test before you enforce
Confirm that at least one administrator can sign in through your identity provider before enabling Force SSO. If the provider is misconfigured or later becomes unreachable, your members cannot sign in and Clav support has to lift the enforcement for you.
Frequently Asked Questions
Any provider that speaks SAML 2.0 or OpenID Connect. That includes Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, JumpCloud, Ping Identity and Auth0. Clav does not depend on provider-specific extensions, so a conformant IdP will work even if it is not on this list.
Only the organization owner. Registering, updating or removing a provider, and enabling Force SSO, are owner-only actions. Every one of them is written to the organization's audit log with the acting user, the source IP and the timestamp.
Domain verification proves that your organization controls the email domain before Clav will route any sign-in through your identity provider. Without it, anyone could register a provider claiming your domain and intercept logins for your users. The provider stays inactive until the DNS TXT record is published and checked.
Passwords are not deleted, but they stop working. With Force SSO enabled, every email and password sign-in and every Google sign-in is rejected for members of your organization — the only accepted path is your identity provider. Turning Force SSO off restores the previous methods.
Yes, and you should. After you verify the domain, the provider is active and users can sign in through it, while the existing methods keep working. Confirm that at least one administrator can sign in through the identity provider before you enable Force SSO. Enabling enforcement without testing can lock your team out.
Your users will not be able to sign in until the provider is reachable again, because Force SSO deliberately removes the fallback paths. If you need access restored urgently, contact Clav support so an operator can disable enforcement for your organization.
It moves the responsibility to your identity provider. When members sign in through SSO, the multi-factor policy and any conditional-access rules configured in your IdP apply. Clav's own Require two-factor policy governs accounts that authenticate directly with Clav.
Membership is still invitation-controlled. A user signing in through your identity provider is joined to your organization only when they have a valid invitation, so an account in your IdP does not by itself grant access to your Clav data.
Yes. An owner can remove the provider at any time from Settings, and the removal is audit-logged. If Force SSO is enabled, turn it off first so your members keep a way to sign in.
Need More Information?
If you have questions about connecting your identity provider, verifying your domain, or enforcing SSO across your organization, please contact us.
Email Support
Contact your administrator or our support team
Documentation
Check our technical documentation for more details