Skip to main content

Overview

Single sign-on lets your team sign in to Tavus with your company credentials, through your own identity provider. SSO is self-serve: a team admin configures and activates it directly from the Tavus Portal, with no back-and-forth with Tavus. Both SAML and OIDC are supported, including Okta, Microsoft Entra ID, Google Workspace, and custom providers.
Only a team admin can configure SSO. If SSO settings aren’t available on your account, reach out to your Tavus account team.

Configure SSO

1

Open your SSO settings

Go to Settings in the Tavus Portal and find the single sign-on section. It shows which step you’re on, so you can stop and come back later.
2

Add and verify your domains

Add each email domain your team signs in with, then verify ownership of each by adding the DNS TXT record shown to your domain’s DNS settings. Verification can take a few minutes to propagate, and only verified domains route sign-ins.
3

Connect your identity provider

Select your identity provider and follow the guided steps to connect it over SAML or OIDC. Tavus shows the service provider details to enter in your provider, and collects your provider’s configuration in return.
4

Verify sign-in

Sign out of Tavus and sign back in through your identity provider. This confirms the connection works end to end, and it’s required before you can activate SSO for your team.
The test sign-in inside the setup flow doesn’t count. An admin has to actually sign in to Tavus through the provider once.
5

Require SSO

Turn on Require SSO to make your identity provider the only way into your team. Every member is moved onto SSO, and signing in with a password, Google, or Apple stops working for them.Until you turn it on, SSO is available but optional - your team can keep using their existing sign-in method while you test.
Setup links open a secure configuration flow and expire after a few minutes. If a link stops working, reopen it from Settings.

Automatic Provisioning

By default, a team is invite-only: setting up SSO doesn’t let anyone in on its own. Turn on just-in-time provisioning if you’d rather have anyone on a verified domain join your team automatically the first time they sign in through your provider. New people always join as members, never as admins. Turning it off applies to future sign-ins only and doesn’t remove anyone who already joined.
With just-in-time provisioning on, anyone with an email address on a verified domain can take a seat in your account without an invitation. Leave it off if you want to approve every member.

FAQ

Can I turn SSO off again?

Yes. Require SSO can be switched off at any time with no preconditions, which restores password, Google, and Apple sign-in. It’s the way back in if your identity provider breaks. Members stay on SSO until you change them individually from the members list.

Can I move one person onto SSO first?

Yes. You can move a single member onto SSO from the members list, and move them back the same way. This is useful for testing your rollout, or for keeping a contractor on a password login while the rest of the team uses your provider.

Nobody can sign in through our provider

Your provider’s signing certificate has most likely expired. Use the certificate renewal option in Settings to upload the new certificate. If your team requires SSO in the meantime, turn Require SSO off to restore password sign-in while you fix the connection.

Why can’t I remove a domain?

Removing a domain is only blocked when it’s your last verified domain and your team still routes sign-ins on it, because Require SSO or just-in-time provisioning is on. Turn the relevant setting off first, or verify another domain, then remove it.

What happens when someone on SSO leaves the team?

Their Tavus account is unlinked from your identity provider and they move to a personal account. Because their work mailbox is usually closed at that point, they generally can’t sign in again on their own - they should contact support if they need access to that account.