Domains and SSO
Register your domains, then choose whether to require single sign-on (SSO) for each one. SSO is set per verified domain — so if you run several storefronts, you can require SSO on some and not others. Everything for domains and SSO lives on this one page.
Domain registration
Three-action workflow
| Step | What happens |
|---|---|
| 1. Add domain | You type the domain into the Add domain dialog and submit |
| 2. Publish TXT record | The setup dialog opens automatically, showing the required DNS TXT record (name + value) with copy buttons. You publish the record at your DNS provider |
| 3. Verify | Back on Firmly Connect, you click Verify now. Firmly looks up the TXT record live |
If the record isn’t found yet, the page surfaces a friendly “DNS changes can take a few minutes to propagate — try again shortly” message rather than a hard error.
Status column
| Status | Meaning |
|---|---|
Pending |
TXT record not yet found |
Verified |
Record matched and recorded |
Removing a domain is deliberate
A confirmation dialog explicitly states that removing a verified domain releases anything bound to it — SSO enforcement, branded hosting — and disables the related functionality immediately for that domain.
Per-domain SSO enforcement switch
Each verified domain has an SSO Enforced switch in the table:
| State | What happens at login |
|---|---|
| OFF | Users on that domain can sign in with any method — OTP, magic link, or SSO |
| ON | The login page blocks OTP and magic link for that domain and only allows the bound Identity Provider. There is no self-service bypass — if the IdP breaks and locks the team out, contact Firmly to recover access |
The switch is disabled with a tooltip (“Verify the domain before enforcing SSO”) until the domain is verified. Enforcement also requires at least one enabled IdP bound to the domain.
SSO configuration
Your SSO providers
Each registered IdP row shows:
- Display name
- Underlying template (e.g. “SAML 2.0”)
- Domains it’s bound to (or “No domains bound”)
- Enabled / disabled status
- Action menu: Edit, Enable / Disable, Delete
Adding a provider
When you add an SSO provider, a picker offers a fixed set of templates:
| Template | Status |
|---|---|
| Generic OIDC | Available now — configurable issuer URL, client ID, client secret |
| SAML 2.0 | Available now — displays the SP Entity ID and ACS URL (Firmly provides these); configurable IdP metadata (file upload or pasted XML), IdP entity ID, SSO URL, X.509 certificate |
| Okta | Coming Soon |
| Microsoft Entra ID | Coming Soon |
| Google Workspace | Coming Soon |
| Auth0 | Coming Soon |
| OneLogin | Coming Soon |
Configuring a provider
Each provider’s settings include:
- Protocol-specific credentials (issuer, client ID/secret for OIDC; metadata XML, certificates for SAML)
- Attribute mapping (e.g. which incoming SAML attribute maps to email)
- List of verified domains this IdP is authorized for
- Enabled switch that flips the IdP on for SSO authentication
Role gating
| Action | Who can do it |
|---|---|
| Add / verify domain | Owner, Primary Owner, Firmly admin |
| Toggle SSO enforcement | Owner, Primary Owner, Firmly admin |
| Remove domain | Owner, Primary Owner, Firmly admin |
| Configure SSO IdPs | Owner, Primary Owner, Firmly admin |
Viewers / Editors see read-only tables.
Related
- Firmly Connect SSO setup guides — per-IdP configuration (Generic OIDC, Generic SAML, domain verification details)
- Audit logs — domain and SSO actions logged here
- Team management