Docs
Firmly Agentic Commerce
Set theme to dark (⇧+D)

SSO

​​ What you get

Centralized Identity Your team logs in to Firmly Connect using the same Identity Provider they already use everywhere else.
Per-Domain Control Each verified email domain has its own IdP configuration. Different domains can use different IdPs.
Strict Enforcement When SSO enforcement is enabled for a domain, OTP and magic-link login are blocked — every user on that domain must authenticate through your IdP.

​​ How SSO works

Setting up SSO is a five-step flow: register a domain, verify ownership, configure an Identity Provider, bind the IdP to the verified domain, and finally turn on enforcement.

You must verify the domain and bind it to an enabled IdP before the SSO Enforced toggle becomes available. This prevents an organization from locking itself out of an unverified domain or a domain with no working IdP.

​​ Per-domain enforcement

Enforcement is scoped to one verified email domain at a time — it is never global.

Example: turning SSO Enforced ON for <merchant>.com affects only users with @<merchant>.com email addresses — users on any other verified domain are unaffected.

When enforcement is ON for a domain:

  • Every user whose email belongs to that domain must complete an SSO sign-in through the bound IdP.
  • One-time-passcode (OTP) and magic-link logins are blocked for that domain. There is no self-service bypass — if the IdP breaks and locks the team out, contact Firmly to recover access.
  • Users on other (unenforced) domains are unaffected and can continue to log in via OTP or magic link.

You can step back from enforcement without deleting any configuration:

  • Disable the IdP — the Enabled toggle on the IdP form turns enforcement OFF everywhere it is bound, while preserving the IdP configuration.
  • Toggle SSO Enforced OFF on a specific domain — users on that domain regain OTP / magic-link access.

​​ Supported protocols

​​ Setup checklist

​​ Verify a domain

Add an email domain in Settings → Domains and prove ownership by publishing a DNS TXT record. See Verify a Domain.

​​ Add an Identity Provider

Open Settings → Single Sign-On, click Add Identity Provider, and choose Generic OIDC or Generic SAML 2.0.

​​ Bind the IdP to your verified domains

On the IdP configuration form, select one or more verified domains under Authorized Domains. At least one domain must be bound before the IdP can be enabled.

​​ Test the connection, then enable the IdP

Click Test Connection to perform a live round trip through your IdP and confirm it succeeds, then turn the Enabled toggle on. Always run a successful Test Connection before enabling the IdP.

​​ Enforce SSO on the domain

Return to Settings → Domains and turn the SSO Enforced toggle on for each domain you want to lock down. See enforcement details.

​​ Next steps