- Microsoft Entra ID, formerly Azure Active Directory (Azure AD)
- Google Workspace
SSO is available on enterprise plans.
These guides use the redirect address of the hosted app. If you run Variable yourself, register your own address instead and configure OAuth through the environment variables in Self-hosted.
How setup works
You create an app in your IdP and send us its credentials; we set up the connection on our side. SSO is not something you switch on in the app.1
Verify your email domain in Variable
SSO is tied to the email domains you own, and only a verified domain can be linked. Follow Verify your domain below.
2
Create the app in your IdP
Follow the guide for Microsoft Entra ID or Google Workspace. It ends with a client ID and a client secret.
3
Send us the credentials
Through an agreed-upon secure channel, send us the provider, the client ID and client secret, the domains to cover (for Microsoft, also your tenant ID), and a contact who can test the sign-in.
4
Invite your team
SSO proves who someone is, but it does not add them to your account. See Invite people first.
5
Test the sign-in
We confirm when the connection is live. Keep an owner signed in until a second person has signed in through SSO.
Verify your domain
You need the admin role to verify a domain.- Go to Settings → Company and find the Domains card.
- Select Add Domain, enter your domain, for example
acme.com, and select [Verify Domain] next to it. - Add the DNS TXT record shown: name it
_variable-domain-verifyon your domain, with the value Variable gives you. DNS changes can take up to 72 hours to propagate. - Select Check now. The domain shows Verified once the record is found.
acme.com does not cover eu.acme.com, so verify and link every domain your people sign in with, and list them all when you contact us. For Google Workspace, also include your primary Workspace domain, even if nobody signs in with it: Google reports it for every account in your organization.
Invite people first
Signing in through your IdP does not by itself give anyone access to your Variable account, so invite people before they sign in:- Go to Settings → Users and select Invite.
- Enter the same email address they use at work, and assign a role.
The Auto-join switch on a verified domain does not apply to SSO sign-ins. Invite people instead.
Keep it working
- Client secret expiry. Microsoft client secrets expire, at most 24 months after they are created. When one does, nobody at your company can sign in through SSO. Create a new secret before the old one lapses and send it to us through an agreed-upon secure channel.
- Keep a way in. Make sure at least one owner has confirmed they can sign in through SSO before you rely on it.
- Offboarding. Disabling a person in your IdP stops new SSO sign-ins, and a session they have open can stay active until it expires. To end someone’s access immediately, also remove them from Settings → Users in Variable.
Troubleshooting
Contact us through your agreed channel with the time of the attempt and the email address used.