Single sign-on
On this page
Single sign-on (SSO) lets you use your work identity to access Specset. Google Workspace, Okta, and Microsoft Entra ID are supported. Organization administrators manage providers under Org Settings → Security & SSO.
Google Workspace setup is coordinated with Specset support. Entra and Okta can be connected from the settings page. Adding a provider does not require every member to use it: choose that separately in Organization security.
Google Workspace
- Contact support@specset.com with the organization and Workspace domains you want to connect.
- Work with Specset support to verify domain ownership and configure the provider. Specset manages the Google OAuth application, so you do not need to create your own OAuth client.
- Once the provider is ready, enter your work email on the Specset sign-in page and choose your organization's Google button.
- Sign in to the Google Workspace account for the configured domain. If you already have a Specset account, complete the linking steps below.
Google Workspace sign-in uses your managed work account. A personal Gmail account does not satisfy the Workspace-domain requirement. Connecting Google does not automatically establish that every sign-in meets an MFA or phishing-resistant policy; coordinate any stronger requirement with Specset support before enforcing it.
Connect Google to an existing account
- Sign in to Specset using your existing method.
- Open Account Settings → Sign-in & security and click Connect Google. This option appears when your organization has an eligible Google Workspace provider.
- Complete Google sign-in with the account that matches your Specset email.
- Follow the Connect Google page to verify your existing sign-in method if prompted. If you belong to organizations that require SSO, you may need to verify through their existing providers.
- Review the connection and click Connect Google to confirm.
Your projects, memberships, and permissions stay with the same account. Linking signs out your other sessions. A matching email address alone does not connect accounts, and completing verification does not replace the final confirmation.
If you start with the Google button on the sign-in page, Specset guides you through the same verification and confirmation. Some protected accounts require administrator-assisted enrollment instead. Share the displayed request ID with Specset support through your organization's approved support process. If it expires, start Google sign-in again.
Microsoft Entra ID
- Under Identity Providers, click Connect Microsoft Entra.
- Sign in with an account that can grant consent for your tenant.
- Specset records the tenant and its verified email domains.
- Test a member sign-in before making SSO required.
Okta
Create an OIDC web application in your Okta organization, then connect it to Specset.
-
In the Okta Admin Console, open Applications → Applications → Create App Integration. Choose OIDC - OpenID Connect and Web Application.
-
Keep Authorization Code enabled and use Client secret authentication.
-
Set the Sign-in redirect URI to:
https://app.specset.com/privateApi/auth/callback -
Under Assignments, grant access to the people or groups who should use Specset.
-
Save the integration and copy its Client ID and Client secret.
-
In Specset, open Org Settings → Security & SSO and click Create Manually under Identity Providers.
-
Choose Okta, then enter a Display name, the Issuer URL, and the client credentials. Use the issuer of the Okta authorization server you configured, such as
https://example.okta.comorhttps://example.okta.com/oauth2/default. -
Save the provider and test a member sign-in. Contact support@specset.com to associate your verified email domains with it.
Provider changes are saved in their own dialogs. The page-level Save button applies to authentication policy, onboarding, and session duration.
Sign in and join an organization
Enter your work email on the sign-in page, then choose your organization's provider button. If the expected button is missing, ask your organization administrator to check the provider and verified-domain setup.
An existing Specset account must be verified before its first link to a new identity provider. For Entra or Okta, sign in to the existing account first and retry the provider connection. For Google, use the guided flow above. New invited accounts follow the invitation and provider setup offered by their organization.
Accepting an invitation or signing in to another organization does not bypass this organization's security requirements. Before making SSO required, confirm that administrators and existing members have a working sign-in or an assisted enrollment path. See Organization security.