SSO
What you get
How SSO works
Setting up SSO is a five-step flow: register a domain, verify ownership, configure an Identity Provider, bind the IdP to the verified domain, and finally turn on enforcement.
You must verify the domain and bind it to an enabled IdP before the SSO Enforced toggle becomes available. This prevents an organization from locking itself out of an unverified domain or a domain with no working IdP.
Per-domain enforcement
Enforcement is scoped to one verified email domain at a time — it is never global.
Example: turning SSO Enforced ON for <merchant>.com affects only users with @<merchant>.com email addresses — users on any other verified domain are unaffected.
When enforcement is ON for a domain:
- Every user whose email belongs to that domain must complete an SSO sign-in through the bound IdP.
- One-time-passcode (OTP) and magic-link logins are blocked for that domain. There is no self-service bypass — if the IdP breaks and locks the team out, contact Firmly to recover access.
- Users on other (unenforced) domains are unaffected and can continue to log in via OTP or magic link.
You can step back from enforcement without deleting any configuration:
- Disable the IdP — the Enabled toggle on the IdP form turns enforcement OFF everywhere it is bound, while preserving the IdP configuration.
- Toggle SSO Enforced OFF on a specific domain — users on that domain regain OTP / magic-link access.
Supported protocols
Setup checklist
Verify a domain
Add an email domain in Settings → Domains and prove ownership by publishing a DNS TXT record. See Verify a Domain.
Add an Identity Provider
Open Settings → Single Sign-On, click Add Identity Provider, and choose Generic OIDC or Generic SAML 2.0.
Bind the IdP to your verified domains
On the IdP configuration form, select one or more verified domains under Authorized Domains. At least one domain must be bound before the IdP can be enabled.
Test the connection, then enable the IdP
Click Test Connection to perform a live round trip through your IdP and confirm it succeeds, then turn the Enabled toggle on. Always run a successful Test Connection before enabling the IdP.
Enforce SSO on the domain
Return to Settings → Domains and turn the SSO Enforced toggle on for each domain you want to lock down. See enforcement details.