> ## Documentation Index
> Fetch the complete documentation index at: https://docs.peepsai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on

> Let your people sign in to Peeps with your company login through SAML single sign-on.

With single sign-on (SSO), your people sign in to Peeps with their company account instead of a separate Peeps login. Peeps supports SSO over SAML 2.0, and Okta is the first identity provider we support.

## How it works

SAML is a standard that lets your identity provider vouch for a user to an app. Two sides take part:

* **Your identity provider** (Okta) knows who your people are and checks their password and MFA.
* **Peeps** trusts your identity provider's word for who is signing in.

A sign-in is a round trip through the browser:

<Steps>
  <Step title="Start at Peeps">
    Someone opens the Peeps login page, chooses **Sign in with SSO**, and enters their work email.
  </Step>

  <Step title="Sign in at Okta">
    Peeps sends them to your Okta, where they sign in, or pass straight through if they already have.
  </Step>

  <Step title="Back to Peeps">
    Okta sends them back to Peeps with a signed statement of who they are. Peeps checks the signature and signs them in.
  </Step>
</Steps>

Okta and Peeps never exchange your users' passwords. Everything passes through the person's browser, signed by Okta.

## Who gets in

Anyone you **assign to the Peeps app in Okta** can sign in, as long as their email is on one of your organization's verified domains. Assigning the app is how you give someone Peeps; there's no separate invite.

* **New people** join your Peeps organization as a **contributor**. You can change their role afterwards under **Settings → Organization → Members**.
* **People who already use Peeps** with the same email keep their account and everything in it. SSO simply becomes another way to sign in to it.
* **People on other email domains**, such as contractors, can't use SSO. Invite them to Peeps as usual.

Signing in with a login link or Google keeps working alongside SSO.

## Removing access

<Warning>
  **Remove people in Okta and in Peeps.** Peeps doesn't yet require SSO, so removing someone in Okta doesn't remove their Peeps access. They can still sign in with a login link or Google, and a session they already have stays open. To remove access, an organization owner also removes them under **Settings → Organization → Members**.

  The reverse applies too: someone you remove only in Peeps, but who is still assigned the app in Okta, joins again the next time they sign in with SSO.
</Warning>

## Getting started

SSO is set up for your organization together with Peeps. Email [support@peepsai.com](mailto:support@peepsai.com) with your organization's name and the email domains your people use, then follow [Set up Okta](/sso/okta).

## Limitations

* Sign-in has to start from the Peeps login page. The Peeps tile on the Okta dashboard doesn't sign you in.
* Roles are managed in Peeps. Okta groups don't map to Peeps roles.
* You can't yet require SSO for everyone in your organization.
