---
title: "Sign-in and SSO"
description: "Configure how your organization signs in — passwords, SSO, and who may join."
canonical: https://ocho.bot/docs/administration/sign-in-and-sso
last_updated: 2026-07-12
---

# Sign-in and SSO

> Configure how your organization signs in — passwords, SSO, and who may join.

> Who can do this: auth administrators.

The **Auth Management** card on Home opens the page that controls your organization's sign-in. The page itself is headed **Authentication** — "Manage how your organization signs in and how new users get access."

## See the current method

The top card, **Current method**, shows what's active: Email & Password, or Single Sign-On (OIDC) / Single Sign-On (SAML) with the provider details.

## Control who can join

Two access modes:

- **Invite only** — only people you add can sign in.
- **Self-service** — anyone from an allowed email domain is provisioned on

first SSO login. When selected, manage the **Allowed email domains** list   right below — self-service is blocked until you add at least one domain.

Changes here save immediately: picking a mode or adding/removing a domain takes effect on click — there is no Save button.

## Set up SSO

1. Copy the displayed **redirect URI** and register it with your identity    provider. 2. Choose **OIDC** (client ID, client secret, issuer URL) or **SAML**    (metadata URL, or entity ID + SSO URL + certificate). 3. Optionally click **Test connection** to validate the configuration    without a live login. 4. Click **Enable SSO**. If SSO is already configured, the card and its    button read **Update SSO** instead.

## Switch back to passwords

**Switch back to email & password** turns SSO off. Because SSO users have no password yet, the confirmation dialog offers **Email new passwords to affected users now** (checked by default); confirm with **Switch to basic auth**. Existing sessions remain valid until they expire.

## Good to know

- Secrets are write-only — the page never redisplays a saved client secret;

updating SSO means re-entering the credentials.

- During company onboarding, the same setup is offered as the Security step,

including **Delegate to Someone** — enter the colleague's full name and   email (both are required).

All docs: https://ocho.bot/docs

---

Ocho — AI knowledge orchestration · [Home](https://ocho.bot/) · [Docs](https://ocho.bot/docs) · [Blog](https://ocho.bot/blog) · [About](https://ocho.bot/about) · [Developers](https://ocho.bot/developers) · [Contact](https://ocho.bot/contact) · [llms.txt](https://ocho.bot/llms.txt)
