Join the waitlist for early access!
Star BG

Join The Waitlist!

Join the Citi to be one of our first creators that get access to brand deals, affiliate program and earn seamlessly!

Login
Help/Articles/Connecting Your Company to Single Sign-On (SSO)
Brands

Connecting Your Company to Single Sign-On (SSO)

Set up enterprise SSO so your team signs in to Fanciti with your company identity provider and joins your brand workspace automatically.

6 min read

Single Sign-On lets your employees access Fanciti with their existing company credentials — no separate passwords, no manual invites. Fanciti connects to your identity provider (IdP) over OpenID Connect, which is supported by Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, and most other enterprise IdPs. When someone on your team signs in through SSO for the first time, their Fanciti account is created automatically and they join your brand workspace with the role you choose.

SSO is available on the Enterprise plan. If your workspace is on another plan, the Single Sign-On card in workspace settings shows a locked state — contact sales to upgrade.

Before you start

You will need three things: admin access to your brand workspace on Fanciti (owner or admin role), admin access to your company identity provider, and a verified company domain. Your allowed email domains must match the company email domain or website domain verified during brand verification — this proves your company owns the domains employees will sign in with.

Setting up the connection

  1. 1
    Open the Single Sign-On card

    Go to Settings → Brands and find the Single Sign-On (SSO) section under your workspace. Only workspace owners and admins can see and edit it.

  2. 2
    Create an app in your identity provider

    In your IdP's admin console, create a new OIDC / OpenID Connect web application for Fanciti. When it asks for a redirect or callback URL, leave the IdP tab open — Fanciti shows you the exact URL to paste after you save the connection.

  3. 3
    Enter the connection details in Fanciti

    Copy the issuer URL, client ID, and client secret from the IdP app into the SSO form. The issuer URL is your IdP's base address (for example https://yourcompany.okta.com) and must be a public https address. The secret is encrypted at rest and never shown again — you can replace it later, but not view it.

  4. 4
    Add your allowed email domains

    List the email domains your employees use, separated by commas (for example company.com, subsidiary.com). Personal email domains like gmail.com are not allowed, and every domain must match your verified company email or website domain before SSO can be enabled.

  5. 5
    Choose the role for new members

    Pick the workspace role that first-time SSO sign-ins receive: Member or Viewer. SSO can never grant admin or owner roles — promote people manually from the Team panel afterwards if needed.

  6. 6
    Save, register the callback URL, and test

    Save the connection, then copy the callback URL shown in the "Identity provider setup" box (it looks like /auth/callback/sso-…) into your IdP app's redirect URL field. Use the Test connection button to confirm Fanciti can reach your IdP, then turn on "Enable SSO sign-in".

How your team signs in

Share your SSO sign-in link — shown in the SSO card as /login/sso/your-brand-handle — with your team, for example in your intranet or password manager. Employees can also enter their company email under "Enterprise single sign-on" on the brand sign-in page, and Fanciti routes them to the right place. Either way they are sent to your identity provider, sign in with company credentials, and land in your brand workspace.

If someone already has a pending invitation to your workspace, signing in through SSO accepts it automatically — no invite link needed.

Managing access and offboarding

SSO members appear in your Team panel like any other member, and you can change their roles or remove them there. Disabling the SSO connection stops new sign-ins immediately. To revoke a departing employee's access to your workspace, remove them from the team — removal takes effect on their next request even if they still have an open session.

Disabling SSO or letting your Enterprise plan lapse blocks new SSO sign-ins, but it does not remove existing members from your workspace. Always remove departed employees from the Team panel as part of your offboarding process.

Was this helpful? Still need help? Ask the community or email support.