Skip to main content
Single sign-on (SSO) lets your team sign in to Vibely with the same company account they use everywhere else, and lets your identity provider (IdP) decide who gets in.
Set up workspace single sign-on (SSO)
SSO is available on the Business plan. The workspace owner or an admin sets it up.
This page covers SSO for your team’s access to Vibely itself. To add sign-in to an app you build, see Authentication.
Sign-in always starts from Vibely: your team enters their work email on the Vibely sign-in page and is sent to your IdP. Starting from a tile in your IdP’s dashboard isn’t supported.

Supported SSO protocols

  • OpenID Connect (OIDC) is recommended. You can set it up end to end yourself.
  • SAML 2.0 works with any SAML IdP. Your IdP’s metadata has to be registered with Vibely’s sign-in service first, which support does for you.
There’s no Vibely app in the Okta or Microsoft Entra gallery. Every setup below uses a custom application.

Prerequisites

  • Admin access to your IdP (Okta, Microsoft Entra ID, Auth0, or another provider).
  • The owner or admin role in a Business workspace.
  • A verified domain. See Verify your domain.

Start SSO setup in Vibely

1

Open Identity

Go to Settings → Access → Identity.
2

Verify your domain

Under Domain verification, confirm the status is Verified.
3

Choose a protocol

Under Single sign-on, pick OIDC or SAML 2.0 in Protocol. The fields change to match.
4

Configure your IdP

Copy the values Vibely shows into your IdP. See the reference below and the guide for your provider.
5

Enter your IdP's details

For OIDC, paste the issuer URL, client ID, and client secret. For SAML, paste the provider ID.
6

Turn it on

Turn on Enable SSO and click Save single sign-on.
7

Set the join role

Under User provisioning, set Role on first SSO login. Start with Viewer if you’re unsure.

IdP configuration reference

  • Application type: web application (a confidential client with a client secret)
  • Grant type: Authorization Code, with PKCE (S256)
  • Redirect URI: https://vibely.sh/api/v1/public/oidc/callback (also shown on the Identity page as Redirect URI)
  • Scopes: openid, email, profile
  • The ID token must include the user’s email.

What Vibely checks on every sign-in

For OIDC, Vibely reads your IdP’s discovery document, requires its issuer to match the URL you entered exactly, and validates the ID token’s signature, issuer, audience, expiry, and nonce before signing anyone in. For both protocols, the email your IdP sends must be on your workspace’s verified domain. A sign-in for someone@other.com is rejected even if your IdP vouches for it.

Require SSO

Once SSO works, you can turn on Require SSO to make your IdP the only way to join the workspace and to use Vibely as a member. It turns off invitations and external collaborators, and signs out any member (except the workspace owner) whose session didn’t come through your IdP, such as a password or Google sign-in. You can also set a Session duration of 24 hours, 48 hours, or 7 days, after which members sign in through your IdP again. See Require SSO and session duration.
Test a sign-in with a colleague’s account before requiring SSO.

Provider-specific setup guides

Complete Start SSO setup in Vibely first so you have the values to copy.

Okta

  1. Applications → Create App Integration → OIDC - OpenID Connect → Web Application.
  2. Grant type: Authorization Code.
  3. Sign-in redirect URI: the Vibely redirect URI.
  4. Assign the people or groups who should get in.
  5. Copy the Client ID and Client secret into Vibely. The issuer is https://<your-org>.okta.com, or your custom authorization server’s issuer if you use one. Use exactly the issuer value from the IdP’s discovery document.

Microsoft Entra ID

  1. App registrations → New registration.
  2. Redirect URI: platform Web, the Vibely redirect URI.
  3. Certificates & secrets → New client secret. Copy the secret’s Value, not its ID.
  4. The issuer is https://login.microsoftonline.com/<tenant-id>/v2.0. Use the v2.0 endpoint: v1.0 reports a different issuer and is rejected.

Auth0

  1. Applications → Create Application → Regular Web Application.
  2. Allowed Callback URLs: the Vibely redirect URI.
  3. Copy the Domain, Client ID, and Client Secret.
  4. The issuer is https://<your-tenant>.auth0.com/. Vibely handles the trailing slash either way.

Configure other providers

Any provider works if it supports one of the protocols:
  • OIDC: the provider must publish /.well-known/openid-configuration at its issuer, support the authorization-code grant with PKCE, and put an email claim in the ID token. Register a confidential web client with the Vibely redirect URI and the openid email profile scopes.
  • SAML 2.0: configure the ACS URL and entity ID, send EmailAddress as the Name ID, and send the metadata URL to Vibely support.

Manage an existing SSO setup

  • Rotate the OIDC client secret: paste the new secret and save. Leaving the field blank keeps the stored secret, so you can change other fields without re-entering it. The secret is stored encrypted and never shown again.
  • Change the domain: changing the email domain clears verification. Verify again before sign-ins resume.
  • Turn SSO off: turn off Enable SSO and save. Sign-in goes back to Google and email.

Signing in

Your team goes to the normal Vibely sign-in page and enters their work email. If the domain is set up for SSO, they’re sent to your IdP. A domain routes to SSO only when all of these are true:
  • Enable SSO is on
  • the domain is verified
  • the workspace is on Business
  • every field the protocol needs is filled in

Troubleshooting

Errors come back to the sign-in page as /login?error=<code>.
An issuer mismatch is almost always a trailing slash or a version difference: Entra v1.0 instead of v2.0, or an Okta custom authorization server whose issuer is /oauth2/<id> rather than your org URL. Open <issuer>/.well-known/openid-configuration in a browser and copy its issuer field exactly.

FAQ

The Business plan.
No. Sign-in starts from the Vibely sign-in page.
No. A workspace has one SSO configuration for its one verified domain.
No. Next time they sign in with their work email, Vibely sends them to your IdP. Their account, projects, and role stay the same.
Through SCIM, yes. Vibely exposes three role groups (Admins, Editors, Viewers) that you map your IdP groups onto. See SCIM.

Identity

Verify your domain and choose how people join.

SCIM

Provision and deprovision members from your IdP.