Enable single sign-on so your team can log in with your corporate identity provider.
What is SSO?
Single Sign-On (SSO) allows your team to authenticate using your corporate identity provider instead of managing separate credentials. 3MotionAI supports SAML 2.0, OIDC, Azure AD, Google Workspace, and Okta. When SSO is enabled, users are redirected to your identity provider for authentication.
How to get started
Configuring SSO for your organization:
Choose your identity provider type (SAML 2.0, OIDC, Azure AD, Google Workspace, or Okta).
Enter the required configuration: SSO URL, certificate or client credentials depending on the provider.
Test the connection to verify that authentication works correctly before enabling for all users.
Enable SSO to redirect all users to your identity provider for login.
Key concepts
Important SSO concepts:
SAML vs OIDC: SAML uses XML-based assertions while OIDC uses JSON Web Tokens. Both are fully supported.
MFA policy: You can enforce multi-factor authentication (optional, required, or disabled) independently of SSO.
Connection status: After configuration, the connection shows as Active, Inactive, or Error. Test regularly to ensure reliability.
Fallback authentication: Even with SSO enabled, Super Admins can always log in with email/password as a fallback.
Common questions
Answers to frequently asked questions:
Can I test SSO before enabling it for all users? Yes, use the Test Connection button to verify the configuration.
What happens if my identity provider goes down? Super Admins can still log in with email/password. Regular users will need to wait for the IdP to recover.
Can I disable SSO after enabling it? Yes, you can disable SSO at any time. Users will revert to email/password authentication.
Is SSO available on all plans? SSO is an enterprise feature. Check your plan's feature list on the Billing page.
