Skip to main content
On the Single Sign-On (SSO) page, workspace admins configure domain verification and SSO connections. Your team can then authenticate through your identity provider.
Open Settings from the Dock (the app bar at the bottom of the screen). Then select Single Sign-On (SSO) under Workspace Settings.This page is visible to admins only.
You manage both domains and SSO connections through the Admin Portal, a hosted WorkOS interface that Default opens for you. Each time you select Add domain or Set up SSO, Default generates a fresh, intent-scoped portal link that opens in that same tab. Portal links are single-use and expire in roughly five minutes. For this reason, Default never pre-generates them.

Domains

The Domains section lists every email domain your workspace has registered for SSO authentication (for example, acme.com). Default fetches the current state of each domain and shows it as a badge.

Add a domain

Select Add domain to open the WorkOS Admin Portal. Follow the steps in the portal to add and verify your domain. Verification usually involves a DNS TXT record. When verification completes, Default shows the domain with a Healthy badge.

Remove a domain

To remove a domain, select the trash icon on its row. Default asks you to type the domain name exactly to confirm, for example acme.com. The removal takes effect only after you confirm.
You cannot remove a domain while any SSO connection is Active or Validating. Remove the SSO connection first.Then delete the domain.Members who sign in via SSO with that email domain lose access when you remove the domain. You cannot undo this.

Single Sign-On

The Single Sign-On section lists the SSO connections your workspace has configured through the Admin Portal. Each connection shows a name, the connection type (such as Okta SAML), and its current state as a badge.

Set up or manage SSO

Select Set up SSO to open the WorkOS Admin Portal. Create your first SSO connection there. After a connection exists, the button changes to Manage SSO. Use it to edit, test, or remove connections.
Set up SSO is disabled until you have at least one verified domain. Default shows a prompt (“Verify a domain to enable SSO setup”) until that condition is met.

Example: verify a domain, then connect SSO

1

Add and verify your domain

In the Domains section, select Add domain. The Admin Portal opens.Enter your domain, for example acme.com. Follow the DNS verification steps.When verification completes, the domain appears with a Healthy badge.
2

Set up your SSO connection

In the Single Sign-On section, select Set up SSO. The Admin Portal opens to the SSO configuration flow.Choose your identity provider, such as Okta or Microsoft Entra. Complete the setup.Activate the connection. The connection appears in Default with an Active badge.
3

Confirm your team can sign in

Ask a team member to sign in with their acme.com email. Default routes them through your identity provider.After this test succeeds, SSO is live for your workspace.