Single sign-on & SCIM

With single sign-on (SSO), people sign in to Twelfth with their company
account — Microsoft Entra ID, Google Workspace, Okta or any SAML 2.0 / OpenID
Connect provider — and your identity provider’s policies (MFA, conditional
access, device rules) apply to Twelfth too. With SCIM provisioning, your
directory adds and removes people from the workspace, so leavers lose access the
moment they’re removed from the app in your directory.

Both live at Settings → Workspace → Security & SSO → Single sign-on and are part of the
Enterprise plan. Only workspace owners and admins can set them up.

Enterprise plan

If the section shows Enterprise rather than a setup panel, single sign-on is
not yet enabled for your workspace. Talk to your Twelfth contact and we’ll switch
it on as part of your agreement.

How it fits together

  • One identity provider per workspace. You register the IdP once; everyone
    whose work email is on your email domain is sent to it when they choose
    Continue with single sign-on on the login page.
  • Existing people keep their accounts. A buyer you invited earlier who
    already signs in with a password is linked to their SSO identity on first
    SSO sign-in — same email, same account, same remits and history.
  • New people join automatically. Someone your IdP asserts who has never used
    Twelfth gets an account and joins the workspace as a member. Owners and
    admins are still appointed in Members.
  • Other sign-in methods stay available. Password, passkey and Google sign-in
    keep working for existing accounts, so nobody is locked out while you set up.

Set it up

Follow the guide for your provider — each one walks through both sides:

Microsoft Entra ID

SAML app registration plus SCIM provisioning from Entra. Open the guide

Google Workspace

Custom SAML app in the Google Admin console. Open the guide

Okta

SAML app integration plus SCIM provisioning from Okta. Open the guide

Other providers & OpenID Connect

Any SAML 2.0 or OIDC identity provider. Open the guide

Every value in the panel is a chip: click it to copy, and it ticks. The ⋯
menu on step 1 exports the whole setup as a Markdown sheet for whoever runs
your IdP, or as a prompt you can paste into ChatGPT, Claude or Copilot to be
walked through your provider’s console screen by screen.

The panel works in the order an IdP administrator does:

  1. Copy Twelfth’s details into your IdP — the Identifier (Entity ID) and
    Reply URL (ACS) shown at the top of the panel, each with a copy button.
  2. Paste your IdP’s details back — the federation metadata URL (or the XML),
    and the email domain your people sign in with.
  3. Prove you own the domain — add the DNS TXT record the panel shows and
    press Check now (the panel also re-checks every 30 seconds). If your
    domain’s DNS is on a provider that supports Domain Connect (Cloudflare,
    GoDaddy, IONOS…), the panel offers Add the record on … — one click on
    their consent screen, and they write the record for you. Sign-in through
    your IdP stays off until the record resolves; it is what stops anyone else
    claiming your domain.
  4. Test with one person, then tell the team.
DNS slower than your go-live?

If your DNS team can’t add the record quickly, ask Twelfth support. Once we’ve
confirmed the workspace owns the domain, we can verify it for you.

Signing in with SSO

On the login page, choose See other login methods →
Continue with single sign-on
, enter your work email, and you’ll be sent to
your company sign-in and back into Twelfth. After the first time, Continue with
single sign-on
is shown as your last-used method.

Directory provisioning (SCIM)

Once SSO is set up, the Directory provisioning section lets your IdP manage
membership over SCIM 2.0:

  1. Press Generate SCIM token. The token is shown once — paste it into
    your IdP’s provisioning settings straight away, together with the Tenant
    URL
    shown above it.
  2. In your IdP, assign the people (or groups) who should have Twelfth.

What provisioning does:

In your directory In Twelfth
Person assigned to the app Joins the workspace as a member (or is linked, if they already have an account)
Person unassigned, deactivated or deleted Becomes a deactivated member: can’t sign in to the workspace; their remits, decisions and history are kept
Person reassigned Reactivated with everything intact
Name changed Updated on their profile

Roles (owner/admin) and remits are not driven by the directory — set them in
Twelfth. Provisioning never deletes anyone, and it will never deactivate the last
active owner.

Tokens last a year. Rotate token issues a new one while the old keeps
working until you Revoke it, so rotation never interrupts provisioning.

Removing SSO

Remove on the identity provider stops SSO for your domain. Nobody is signed
out; the next sign-in simply falls back to password, passkey or Google. You can
register a provider again at any time. Disconnect on directory provisioning
stops SCIM and revokes its tokens; existing members are untouched.