Skip to main content

Single sign-on

With single sign-on (SSO), members of your organization sign in to VoisX through your own identity provider (IdP), such as Microsoft Entra ID, Okta or Google Workspace. You can then require SSO so that password sign-in stops for your domain.

VoisX supports SAML 2.0 and OpenID Connect (OIDC).

You need the organization Owner or Admin role to set up SSO.

Before you start​

SSO matches people to your organization by their email domain. Verify your domain under Organization → Domains first.

Connect your identity provider​

  1. Open Organization → Security.

  2. Under Connect an identity provider, choose the protocol. You can't change the protocol later without removing the connection and connecting again.

  3. Fill in the details from your IdP:

    OpenID Connect

    FieldWhere to find it
    Client IDThe application you registered in your IdP.
    Client secretThe same application. It is stored securely and never shown again. To keep the current secret when you edit the connection, leave this blank.
    Authorization endpointYour IdP's OIDC discovery document.
    Token endpointYour IdP's OIDC discovery document.
    Userinfo endpointYour IdP's OIDC discovery document.
    IssuerYour IdP's OIDC discovery document.

    SAML 2.0

    FieldWhere to find it
    Single sign-on URLYour IdP's SAML metadata.
    Entity IDYour IdP's SAML metadata.
    Signing certificateYour IdP's signing certificate, base64-encoded DER.
  4. Click Create connection.

  5. Click Enable SSO, then Test connection to check the configuration.

How members sign in​

On the sign-in page at app.voisx.ai, a member enters their work email and clicks Login with SSO. VoisX finds your organization's connection from the email domain and sends them to your IdP.

Require SSO​

Once the connection is enabled and tested, click Require SSO (with grace period).

  • A grace period starts. The console shows the date it ends.
  • Until then, members can still sign in with a password.
  • When the grace period ends, password sign-in stops for your domain and members must use SSO.

Click Make optional to allow password sign-in again.

Keep the connection healthy​

  • For SAML, the console shows when your IdP's signing certificate expires and warns you before it does. Update the certificate in time to avoid failed sign-ins.
  • Edit connection changes the IdP details.
  • Disable SSO turns it off without deleting the configuration.
  • Remove SSO deletes the connection. Members can then no longer sign in through SSO. This can't be undone.
Was this page helpful?