> **For coding agents and LLMs:** This is one page from the Social Fetch docs (markdown export). For curated orientation and workflow guidance, start with [`/llms.txt`](https://www.socialfetch.dev/llms.txt); for agent onboarding and crawl rules, use [`/agents.txt`](https://www.socialfetch.dev/agents.txt); for the full endpoint list with links to pages like this one, use [`/llms-endpoints.txt`](https://www.socialfetch.dev/llms-endpoints.txt); for one platform's parameters and curls, use [`/llms-{platform}.txt`](https://www.socialfetch.dev/llms-tiktok.txt); use [`/llms.json`](https://www.socialfetch.dev/llms.json) when you need structured JSON for tool registration.

## This page

- **On-site (HTML):** [https://www.socialfetch.dev/docs/single-sign-on](https://www.socialfetch.dev/docs/single-sign-on)
- **Markdown (.mdx) URL:** [https://www.socialfetch.dev/docs/single-sign-on.mdx](https://www.socialfetch.dev/docs/single-sign-on.mdx)

## API base URL and authentication

- **API origin (from OpenAPI `servers`):** `https://api.socialfetch.dev`
- **Authentication:** send `x-api-key: sfk_...` on `/v1/**` and `/v2/**` routes unless the operation is explicitly anonymous (check OpenAPI `security`, the [API reference hub](https://www.socialfetch.dev/docs/api.mdx), [`/llms.txt`](https://www.socialfetch.dev/llms.txt), or [`/llms.json`](https://www.socialfetch.dev/llms.json) for each route).
- **OpenAPI JSON:** [https://www.socialfetch.dev/openapi.json](https://www.socialfetch.dev/openapi.json)

## Recommended docs entrypoints (this site)

- [Documentation overview](https://www.socialfetch.dev/docs.mdx) — top-level orientation (markdown).
- [Quickstart](https://www.socialfetch.dev/docs/quickstart.mdx) — authenticate with `x-api-key`, validate auth with `whoami`, and understand the JSON envelope.
- [SDK](https://www.socialfetch.dev/docs/sdk.mdx) — official TypeScript SDK guide, including `SocialFetchClient`, `Result`, and `unwrap()`.
- [Capability matrix](https://www.socialfetch.dev/docs/capability-matrix.mdx) — every operation with identifiers, pagination, outcomes, media download, credits, and its SDK method. Generated from OpenAPI, so use it for route selection instead of scanning individual pages.
- [Recipes](https://www.socialfetch.dev/docs/recipes.mdx) — copyable workflows (brand monitoring, transcripts, Ad Library, creator scoring, Reddit research) with credit callouts and SDK examples.
- [Integrations](https://www.socialfetch.dev/docs/integrations.mdx) — MCP for AI clients, n8n verified node, Apify Store Actors, Make custom app, SDK, and REST API connection paths.
- [MCP product page](https://www.socialfetch.dev/mcp) — hosted MCP overview, OAuth, Skills install.
- [MCP integration](https://www.socialfetch.dev/docs/integrations/mcp.mdx) — hosted `/mcp` server, OAuth, Cursor/VS Code/Claude install snippets, 237 endpoint tools, plus docs_search/docs_read for implementation help.
- [n8n integration](https://www.socialfetch.dev/docs/integrations/n8n.mdx) — install `n8n-nodes-socialfetch`, credentials, and workflow examples.
- [Apify integration](https://www.socialfetch.dev/docs/integrations/apify.mdx) — Store Actors under @social-fetch, PPE billing, dataset export, and quick start.
- [Make integration](https://www.socialfetch.dev/docs/integrations/make.mdx) — custom app modules for Make scenarios, API key credentials, and module catalog.
- [`/llms-endpoints.txt`](https://www.socialfetch.dev/llms-endpoints.txt) — every documented operation with a direct link to that route's agent-readable markdown page (prefer this over parsing OpenAPI).
- [`/llms-{platform}.txt`](https://www.socialfetch.dev/llms-tiktok.txt) — per-platform endpoint files generated from OpenAPI (parameters, credits, curls).
- [`/agents.txt`](https://www.socialfetch.dev/agents.txt) — agent crawl/onboarding file with capabilities, auth rules, and allowlist.
- [`/llms.json`](https://www.socialfetch.dev/llms.json) — structured machine-readable operation inventory with parameter names, pagination, outcomes, credits, and SDK mapping.
- [API reference hub](https://www.socialfetch.dev/docs/api.mdx) — human-friendly index of operations with links into generated pages.
- [Errors](https://www.socialfetch.dev/docs/errors.mdx) — shared error envelope and HTTP status guidance.
- [Credits](https://www.socialfetch.dev/docs/credits.mdx) — metering, `402`, and planning batch jobs.
- Outcome semantics such as `found`, `not_found`, and `private` are documented in [Errors](https://www.socialfetch.dev/docs/errors.mdx) and on operation pages when present in the OpenAPI contract.

## Markdown docs convention

- Every docs page has a markdown twin: append **`.mdx`** to the docs pathname (for example `/docs/quickstart` → `/docs/quickstart.mdx`).
- Agents that send `Accept: text/markdown` on `/docs/**` HTML URLs may receive markdown directly (same URL, `Vary: Accept`).
- Published blog posts use the same convention: `/blog/{slug}` → `/blog/{slug}.mdx`, or `Accept: text/markdown` on the HTML URL (`Vary: Accept`).

---
# Single sign-on and directory sync (https://www.socialfetch.dev/docs/single-sign-on)

Single sign-on and directory sync are an add-on on Scale ($149 per month), self-serve from **Billing → Add-ons**, and included with Enterprise. Once the add-on is on, the settings below appear for the workspace owner. Both are owner-only. See [Add-ons](/docs/credits#add-ons) for billing details.

## Single sign-on

Social Fetch supports single sign-on over **OpenID Connect**. Each workspace can register one provider.

### Set up

1. Open **Team → Single sign-on**.
2. Enter your provider's issuer URL, your company email domain, and the client ID and secret. Provider endpoints must use `https` on the default port (443) at a public host.
3. Allow the redirect URL shown on the page at your provider.
4. Add the DNS `TXT` record shown on the page to your domain to prove you own it, then choose **Verify**. The code is valid for 7 days. Nobody can sign in through the provider before this succeeds, and one domain can belong to one workspace.

### Signing in

People with an email at the verified domain choose **Sign in with SSO** on the sign-in page. Their first sign-in creates their account and adds them to the workspace as a **Member**. This uses the same [seat limit](/docs/teams#seats) as invitations; if the workspace is full, they see that there are no free seats. Owners raise roles afterwards. Accounts with two-factor authentication still complete their second step.

### Require SSO

Once the domain is verified and you have signed in through the provider yourself, an owner can turn on **Require SSO for this workspace**. From then on:

* Members without an SSO session get `403 forbidden` with `reason: sso_required` for that workspace, and the dashboard sends them to a page explaining why.
* AI app (MCP) connections need a live SSO session.
* API keys are unaffected.

If your provider breaks while this is on, an owner can sign in with Google, GitHub, or email and password (the sign-in must be under 10 minutes old), open the workspace, and choose **Owner recovery: Turn off required single sign-on**. This only lets them turn the requirement off, and it is recorded in the activity log.

Removing someone from the workspace does not remove their provider access; while they can still sign in through it, they rejoin on their next sign-in. Deprovision them at your provider, or use directory sync below.

## Directory sync (SCIM 2.0)

Directory sync provisions and removes people from your identity provider (such as Okta or Microsoft Entra ID) automatically. It handles users only, not groups, and needs a verified single sign-on domain.

### Set up

1. Open **Team → Directory sync** and choose **Generate token**. The token is shown once, so copy it.
2. In your identity provider's SCIM settings, enter the base URL shown on the page (`https://api.socialfetch.dev/scim/v2`) and the token as a Bearer token.

**Rotate** replaces the token and the old one stops working at once. **Revoke** deletes it; everyone keeps their access.

### What it does

| Operation                                | Behaviour                                                                                                                                                                                                 |
| ---------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Create user (`POST /Users`)              | Adds the person as a **Member**, within the seat limit. Only addresses at your verified single sign-on domain are accepted. Roles in the request are ignored; directory sync never grants Owner or Admin. |
| Read, list, filter                       | `GET /Users` and `GET /Users/{id}`. Filters: `userName`, `externalId`, `id`, `active` with `eq`. Pages hold up to 100.                                                                                    |
| Update (`PUT`, `PATCH`)                  | Updates names and the active flag. The email can't be changed.                                                                                                                                            |
| Deactivate (`active: false`) or `DELETE` | Removes their access to the workspace and disables the API keys they made for it. Their account is not deleted. Setting `active: true` again restores access if a seat is free.                           |

Owners can't be deprovisioned; change their role on the Team page first. Discovery endpoints (`/ServiceProviderConfig`, `/ResourceTypes`, `/Schemas`) are available for provider set-up.