Skip to main content
Single sign-on (SSO) lets people sign in to Variable with the account they already use at work. Your identity provider (IdP) — the system that holds your company’s user accounts — vouches for who they are, so nobody needs a separate Variable password, and disabling someone in your IdP stops them signing in through SSO. Variable connects to your IdP over OpenID Connect (OIDC), an identity layer built on OAuth 2.0. We support two providers:
  • Microsoft Entra ID, formerly Azure Active Directory (Azure AD)
  • Google Workspace
SSO is available on enterprise plans.
These guides use the redirect address of the hosted app. If you run Variable yourself, register your own address instead and configure OAuth through the environment variables in Self-hosted.

How setup works

You create an app in your IdP and send us its credentials; we set up the connection on our side. SSO is not something you switch on in the app.
1

Verify your email domain in Variable

SSO is tied to the email domains you own, and only a verified domain can be linked. Follow Verify your domain below.
2

Create the app in your IdP

Follow the guide for Microsoft Entra ID or Google Workspace. It ends with a client ID and a client secret.
3

Send us the credentials

Through an agreed-upon secure channel, send us the provider, the client ID and client secret, the domains to cover (for Microsoft, also your tenant ID), and a contact who can test the sign-in.
4

Invite your team

SSO proves who someone is, but it does not add them to your account. See Invite people first.
5

Test the sign-in

We confirm when the connection is live. Keep an owner signed in until a second person has signed in through SSO.

Verify your domain

You need the admin role to verify a domain.
  1. Go to Settings → Company and find the Domains card.
  2. Select Add Domain, enter your domain, for example acme.com, and select [Verify Domain] next to it.
  3. Add the DNS TXT record shown: name it _variable-domain-verify on your domain, with the value Variable gives you. DNS changes can take up to 72 hours to propagate.
  4. Select Check now. The domain shows Verified once the record is found.
Leave the TXT record in place. Variable re-checks it, and Microsoft sign-ins stop for a domain that is no longer verified. Domains are matched exactly. acme.com does not cover eu.acme.com, so verify and link every domain your people sign in with, and list them all when you contact us. For Google Workspace, also include your primary Workspace domain, even if nobody signs in with it: Google reports it for every account in your organization.

Invite people first

Signing in through your IdP does not by itself give anyone access to your Variable account, so invite people before they sign in:
  1. Go to Settings → Users and select Invite.
  2. Enter the same email address they use at work, and assign a role.
Someone who signs in without an invitation is not added to your account. Instead, Variable asks them to set up a new company account of their own. If that happens, sign them out, invite them, and have them sign in again.
The Auto-join switch on a verified domain does not apply to SSO sign-ins. Invite people instead.

Keep it working

  • Client secret expiry. Microsoft client secrets expire, at most 24 months after they are created. When one does, nobody at your company can sign in through SSO. Create a new secret before the old one lapses and send it to us through an agreed-upon secure channel.
  • Keep a way in. Make sure at least one owner has confirmed they can sign in through SSO before you rely on it.
  • Offboarding. Disabling a person in your IdP stops new SSO sign-ins, and a session they have open can stay active until it expires. To end someone’s access immediately, also remove them from Settings → Users in Variable.

Troubleshooting

Contact us through your agreed channel with the time of the attempt and the email address used.