Docs
Firmly Agentic Commerce
Set theme to dark (⇧+D)

Domains and SSO

Register your domains, then choose whether to require single sign-on (SSO) for each one. SSO is set per verified domain — so if you run several storefronts, you can require SSO on some and not others. Everything for domains and SSO lives on this one page.

​​ Domain registration

​​ Three-action workflow

Step What happens
1. Add domain You type the domain into the Add domain dialog and submit
2. Publish TXT record The setup dialog opens automatically, showing the required DNS TXT record (name + value) with copy buttons. You publish the record at your DNS provider
3. Verify Back on Firmly Connect, you click Verify now. Firmly looks up the TXT record live

If the record isn’t found yet, the page surfaces a friendly “DNS changes can take a few minutes to propagate — try again shortly” message rather than a hard error.

​​ Status column

Status Meaning
Pending TXT record not yet found
Verified Record matched and recorded

​​ Removing a domain is deliberate

A confirmation dialog explicitly states that removing a verified domain releases anything bound to it — SSO enforcement, branded hosting — and disables the related functionality immediately for that domain.

​​ Per-domain SSO enforcement switch

Each verified domain has an SSO Enforced switch in the table:

State What happens at login
OFF Users on that domain can sign in with any method — OTP, magic link, or SSO
ON The login page blocks OTP and magic link for that domain and only allows the bound Identity Provider. There is no self-service bypass — if the IdP breaks and locks the team out, contact Firmly to recover access

The switch is disabled with a tooltip (“Verify the domain before enforcing SSO”) until the domain is verified. Enforcement also requires at least one enabled IdP bound to the domain.

​​ SSO configuration

​​ Your SSO providers

Each registered IdP row shows:

  • Display name
  • Underlying template (e.g. “SAML 2.0”)
  • Domains it’s bound to (or “No domains bound”)
  • Enabled / disabled status
  • Action menu: Edit, Enable / Disable, Delete

​​ Adding a provider

When you add an SSO provider, a picker offers a fixed set of templates:

Template Status
Generic OIDC Available now — configurable issuer URL, client ID, client secret
SAML 2.0 Available now — displays the SP Entity ID and ACS URL (Firmly provides these); configurable IdP metadata (file upload or pasted XML), IdP entity ID, SSO URL, X.509 certificate
Okta Coming Soon
Microsoft Entra ID Coming Soon
Google Workspace Coming Soon
Auth0 Coming Soon
OneLogin Coming Soon

​​ Configuring a provider

Each provider’s settings include:

  • Protocol-specific credentials (issuer, client ID/secret for OIDC; metadata XML, certificates for SAML)
  • Attribute mapping (e.g. which incoming SAML attribute maps to email)
  • List of verified domains this IdP is authorized for
  • Enabled switch that flips the IdP on for SSO authentication

​​ Role gating

Action Who can do it
Add / verify domain Owner, Primary Owner, Firmly admin
Toggle SSO enforcement Owner, Primary Owner, Firmly admin
Remove domain Owner, Primary Owner, Firmly admin
Configure SSO IdPs Owner, Primary Owner, Firmly admin

Viewers / Editors see read-only tables.