Overview
Single sign-on lets your team sign in to Tavus with your company credentials, through your own identity provider. SSO is self-serve: a team admin configures and activates it directly from the Tavus Portal, with no back-and-forth with Tavus. Both SAML and OIDC are supported, including Okta, Microsoft Entra ID, Google Workspace, and custom providers.Only a team admin can configure SSO. If SSO settings aren’t available on your account, reach out to your Tavus account team.
Configure SSO
1
Open your SSO settings
Go to Settings in the Tavus Portal and find the single sign-on section. It shows which step you’re on, so you can stop and come back later.
2
Add and verify your domains
Add each email domain your team signs in with, then verify ownership of each by adding the DNS
TXT record shown to your domain’s DNS settings. Verification can take a few minutes to propagate, and only verified domains route sign-ins.3
Connect your identity provider
Select your identity provider and follow the guided steps to connect it over SAML or OIDC. Tavus shows the service provider details to enter in your provider, and collects your provider’s configuration in return.
4
Verify sign-in
Sign out of Tavus and sign back in through your identity provider. This confirms the connection works end to end, and it’s required before you can activate SSO for your team.
The test sign-in inside the setup flow doesn’t count. An admin has to actually sign in to Tavus through the provider once.
5
Require SSO
Turn on Require SSO to make your identity provider the only way into your team. Every member is moved onto SSO, and signing in with a password, Google, or Apple stops working for them.Until you turn it on, SSO is available but optional - your team can keep using their existing sign-in method while you test.
Setup links open a secure configuration flow and expire after a few minutes. If a link stops working, reopen it from Settings.

