Single sign-on and directory sync
Let a team sign in with its company identity provider and keep membership in step with your directory — OpenID Connect and SCIM 2.0
Single sign-on and directory sync are an add-on on Scale ($149 per month), self-serve from Billing → Add-ons, and included with Enterprise. Once the add-on is on, the settings below appear for the workspace owner. Both are owner-only. See Add-ons for billing details.
Single sign-on
Social Fetch supports single sign-on over OpenID Connect. Each workspace can register one provider.
Set up
- Open Team → Single sign-on.
- Enter your provider's issuer URL, your company email domain, and the client ID and secret. Provider endpoints must use
httpson the default port (443) at a public host. - Allow the redirect URL shown on the page at your provider.
- Add the DNS
TXTrecord shown on the page to your domain to prove you own it, then choose Verify. The code is valid for 7 days. Nobody can sign in through the provider before this succeeds, and one domain can belong to one workspace.
Signing in
People with an email at the verified domain choose Sign in with SSO on the sign-in page. Their first sign-in creates their account and adds them to the workspace as a Member. This uses the same seat limit as invitations; if the workspace is full, they see that there are no free seats. Owners raise roles afterwards. Accounts with two-factor authentication still complete their second step.
Require SSO
Once the domain is verified and you have signed in through the provider yourself, an owner can turn on Require SSO for this workspace. From then on:
- Members without an SSO session get
403 forbiddenwithreason: sso_requiredfor that workspace, and the dashboard sends them to a page explaining why. - AI app (MCP) connections need a live SSO session.
- API keys are unaffected.
If your provider breaks while this is on, an owner can sign in with Google, GitHub, or email and password (the sign-in must be under 10 minutes old), open the workspace, and choose Owner recovery: Turn off required single sign-on. This only lets them turn the requirement off, and it is recorded in the activity log.
Removing someone from the workspace does not remove their provider access; while they can still sign in through it, they rejoin on their next sign-in. Deprovision them at your provider, or use directory sync below.
Directory sync (SCIM 2.0)
Directory sync provisions and removes people from your identity provider (such as Okta or Microsoft Entra ID) automatically. It handles users only, not groups, and needs a verified single sign-on domain.
Set up
- Open Team → Directory sync and choose Generate token. The token is shown once, so copy it.
- In your identity provider's SCIM settings, enter the base URL shown on the page (
https://api.socialfetch.dev/scim/v2) and the token as a Bearer token.
Rotate replaces the token and the old one stops working at once. Revoke deletes it; everyone keeps their access.
What it does
| Operation | Behaviour |
|---|---|
Create user (POST /Users) | Adds the person as a Member, within the seat limit. Only addresses at your verified single sign-on domain are accepted. Roles in the request are ignored; directory sync never grants Owner or Admin. |
| Read, list, filter | GET /Users and GET /Users/{id}. Filters: userName, externalId, id, active with eq. Pages hold up to 100. |
Update (PUT, PATCH) | Updates names and the active flag. The email can't be changed. |
Deactivate (active: false) or DELETE | Removes their access to the workspace and disables the API keys they made for it. Their account is not deleted. Setting active: true again restores access if a seat is free. |
Owners can't be deprovisioned; change their role on the Team page first. Discovery endpoints (/ServiceProviderConfig, /ResourceTypes, /Schemas) are available for provider set-up.