Skip to main content

Single Sign-On (SSO)

SSO lets your organization authenticate through your existing identity provider (IdP) instead of username/password or Google SSO. All members sign in through your IdP, and access is revoked automatically when a user is offboarded there. SSO is available on the Enterprise plan. Navigate to Settings > SSO to configure.

Supported identity providers

Okta

SAML 2.0 and OIDC. Most common enterprise IdP. Full provisioning support.

Azure AD / Entra

SAML 2.0 and OIDC. Native Microsoft identity for M365 organizations.

Google Workspace

OIDC. For organizations using Google as their identity provider.

OneLogin

SAML 2.0. Enterprise SSO with role mapping support.
Any SAML 2.0 or OIDC-compatible identity provider is supported. PingFederate, JumpCloud, Auth0, and custom IdPs all work.

How it works

Dacard SSO is powered by Clerk. Configuration is handled during enterprise onboarding you will not configure it directly in the app UI. The setup process:
1

Contact support

Email support@dacard.ai with your identity provider name and the email domain(s) to protect.
2

Configure your IdP

Our team sends you the Dacard SAML metadata URL or OIDC client credentials. You add a new application in your IdP using these values.
3

Verify the connection

Our team verifies the connection and enables SSO for your domain.
4

Enforce SSO

Once verified, you can enable Enforce SSO. All members on your domain must authenticate via your IdP. Email/password and social logins are disabled for your domain.

Enforcing SSO

When SSO is enforced:
  • All members with your email domain must sign in through your IdP
  • Email/password logins are disabled for your domain
  • Members who cannot authenticate through the IdP lose access
  • New sign-ups on your domain are routed through your IdP automatically
Enabling SSO enforcement immediately locks out any members who are not yet provisioned in your IdP. Confirm IdP provisioning is complete before enforcing.

Combine with SCIM provisioning

SSO handles authentication. For automated user provisioning and deprovisioning, pair SSO with SCIM. Together they ensure that:
  • New hires get Dacard access automatically when added in your IdP
  • Departing employees lose access immediately when deactivated in your IdP
  • No manual user management is needed in Dacard

Requirements

RequirementDetail
PlanEnterprise
ConfigurationHandled by Dacard during onboarding
Setup timeTypically 1-2 business days
Supportsupport@dacard.ai

SCIM provisioning

Automate user provisioning alongside SSO.

Plans & Billing

SSO is an Enterprise plan feature.