# Single sign-on (/en/docs/platform/security/sso)



CentralCSP supports single sign-on (SSO) through your existing identity provider. Members sign in with your provider instead of a CentralCSP password.

CentralCSP builds the connection for you. There is no self-service SSO screen in the dashboard, so the setup starts with a request.

## Before you start [#before-you-start]

Single sign-on is included in the Scale and Enterprise plans. Compare plans on the [pricing page](/pricing) or under **Settings** > **Billing**.

Have your identity provider ready. You need someone who can supply its metadata and approve a new application.

## Supported identity providers [#supported-identity-providers]

Support is at the protocol level rather than per vendor. Any provider that speaks Security Assertion Markup Language (SAML) is supported, and so is any provider that speaks OpenID Connect (OIDC).

Providers such as Okta, Microsoft Entra ID, Google Workspace, OneLogin, and JumpCloud all speak one of these two protocols. If your provider offers either one, CentralCSP can connect to it.

## Request a connection [#request-a-connection]

1. Go to the [SSO request form](/contact/?topic=sso).
2. Name your workspace and the identity provider you use.
3. Send the request.

CentralCSP replies with the values your provider needs, configures the connection, and tells you when sign-in is ready to test. Test with one account before you move the whole team across.

## What SSO does not change [#what-sso-does-not-change]

Single sign-on governs how members sign in. It does not govern what they reach once they are in.

Roles, groups, and website access stay under **Team** and are managed in CentralCSP. Removing someone from your identity provider stops them signing in, so remove their CentralCSP membership as well when they leave.

Two-factor enforcement is separate. If your provider already enforces multi-factor authentication, you may not need the CentralCSP setting as well. For more information, refer to [Two-factor enforcement](/en/docs/platform/security/mfa).

## Next steps [#next-steps]

* [Platform security](/en/docs/platform/security/platform-security)
* [Roles and permissions](/en/docs/platform/team/roles-and-permissions)
* [Two-factor enforcement](/en/docs/platform/security/mfa)
