> ## Documentation Index
> Fetch the complete documentation index at: https://docs.variable.global/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on

> Let your team sign in to Variable with their Microsoft Entra ID (Azure AD) or Google Workspace account

Single sign-on (SSO) lets people sign in to Variable with the account they already use at work. Your identity provider (IdP) — the system that holds your company's user accounts — vouches for who they are, so nobody needs a separate Variable password, and disabling someone in your IdP stops them signing in through SSO.

Variable connects to your IdP over OpenID Connect (OIDC), an identity layer built on OAuth 2.0. We support two providers:

* **Microsoft Entra ID**, formerly Azure Active Directory (Azure AD)
* **Google Workspace**

<Note>
  SSO is available on enterprise plans.
</Note>

<Note>
  These guides use the redirect address of the hosted app. If you run Variable yourself, register your own address instead and configure OAuth through the environment variables in [Self-hosted](/docs/self-hosted).
</Note>

## How setup works

You create an app in your IdP and send us its credentials; we set up the connection on our side. SSO is not something you switch on in the app.

<Steps>
  <Step title="Verify your email domain in Variable">
    SSO is tied to the email domains you own, and only a verified domain can be linked. Follow [Verify your domain](#verify-your-domain) below.
  </Step>

  <Step title="Create the app in your IdP">
    Follow the guide for [Microsoft Entra ID](/docs/sso/azure-ad) or [Google Workspace](/docs/sso/google-workspace). It ends with a client ID and a client secret.
  </Step>

  <Step title="Send us the credentials">
    Through an agreed-upon secure channel, send us the provider, the client ID and client secret, the domains to cover (for Microsoft, also your tenant ID), and a contact who can test the sign-in.
  </Step>

  <Step title="Invite your team">
    SSO proves who someone is, but it does not add them to your account. See [Invite people first](#invite-people-first).
  </Step>

  <Step title="Test the sign-in">
    We confirm when the connection is live. Keep an owner signed in until a second person has signed in through SSO.
  </Step>
</Steps>

## Verify your domain

You need the admin role to verify a domain.

1. Go to **Settings** → **Company** and find the **Domains** card.
2. Select **Add Domain**, enter your domain, for example `acme.com`, and select **\[Verify Domain]** next to it.
3. Add the DNS TXT record shown: name it `_variable-domain-verify` on your domain, with the value Variable gives you. DNS changes can take up to 72 hours to propagate.
4. Select **Check now**. The domain shows **Verified** once the record is found.

Leave the TXT record in place. Variable re-checks it, and Microsoft sign-ins stop for a domain that is no longer verified.

Domains are matched exactly. `acme.com` does not cover `eu.acme.com`, so verify and link every domain your people sign in with, and list them all when you contact us. For Google Workspace, also include your primary Workspace domain, even if nobody signs in with it: Google reports it for every account in your organization.

## Invite people first

Signing in through your IdP does not by itself give anyone access to your Variable account, so invite people before they sign in:

1. Go to **Settings** → **Users** and select **Invite**.
2. Enter the same email address they use at work, and assign a role.

Someone who signs in without an invitation is not added to your account. Instead, Variable asks them to set up a new company account of their own. If that happens, sign them out, invite them, and have them sign in again.

<Note>
  The **Auto-join** switch on a verified domain does not apply to SSO sign-ins. Invite people instead.
</Note>

## Keep it working

* **Client secret expiry.** Microsoft client secrets expire, at most 24 months after they are created. When one does, nobody at your company can sign in through SSO. Create a new secret before the old one lapses and send it to us through an agreed-upon secure channel.
* **Keep a way in.** Make sure at least one owner has confirmed they can sign in through SSO before you rely on it.
* **Offboarding.** Disabling a person in your IdP stops new SSO sign-ins, and a session they have open can stay active until it expires. To end someone's access immediately, also remove them from **Settings** → **Users** in Variable.

## Troubleshooting

| What you see | Likely cause | What to do |
| :- | :- | :- |
| The sign-in page asks for a password instead of sending you to your IdP | The email's domain is not linked to a connection | Confirm the exact domain shows **Verified** and was on the list you sent us, then contact us |
| A password is rejected with a message that the domain is managed by your organization's SSO provider | The connection for the domain is switched off. Password sign-in is blocked for the domain and the sign-in page does not send people to your IdP | Contact us to switch the connection on |
| A setup screen asking for a company name | The person was not invited to your account | Invite them from **Settings** → **Users**, then have them sign in again |
| Back on the sign-in page with no message | Variable or your IdP rejected the sign-in: a wrong or expired client secret, a tenant mismatch, a different account than the address typed, a sign-in that did not start on Variable's sign-in page in the same browser, a Google account whose Workspace domain is not linked to the connection, or more than one matching user account belonging to a company | Start again from Variable's sign-in page, typing the address of the account you sign in with. If it happens again, contact us with the time of the attempt: we see the reason in our logs |
| **No access** screen | Variable found more than one matching user account and none of them belongs to a company, or none of the Microsoft account's addresses is on a verified domain linked to the connection | Check the domain still shows **Verified**, then contact us with the address they sign in with |

Contact us through your agreed channel with the time of the attempt and the email address used.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.