# Authentication & SSO

> Part of the NocoDB documentation (Product docs > Account & Billing). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication
Last updated: 2026-09-25

Learn about different methods available for authentication with NocoDB.

This section provides an overview about different mechanisms available for authentication in NocoDB.

# Email and password based

This is the default form based authentication mechanism available in NocoDB. Users can sign up using email and password and then login using the same credentials.

# Two-Factor Authentication (2FA)

Two-factor authentication adds a second layer of security to your account by requiring a time-based verification code from an authenticator app in addition to your password. Once enabled, you'll need both your password and a 6-digit code to sign in.

Please follow the details in the article to set up [Two-Factor Authentication](/docs/product/account-settings/authentication/two-factor-authentication).

# Single Sign On (SSO)

SSO is a session and user authentication service that permits a user to use one set of login credentials to access multiple applications. The service authenticates the end user for all the applications the user has been given rights to and eliminates further prompts when the user switches applications during the same session.

SSO functionality is achieved by establishing a connection with an identity provider (IdP), which serves as a repository for managing users digital identities within the digital or cloud-based ecosystem. Through the use of protocols like the Security Assertion Markup Language (SAML 2.0), such as in the case of NocoDB, SSO facilitates the secure exchange of authentication data between the identity provider and the service providers.

### Google OAuth

Google OAuth, short for Open Authorization, is a widely used and standardized protocol that facilitates secure authentication and authorization processes, particularly in the context of web and mobile applications. Developed by Google, OAuth enables users to grant third-party applications limited access to their resources without exposing their credentials. This authorization framework is based on token-based authentication, where users can log in using their Google credentials, and developers can obtain an access token to interact with Google APIs on the user's behalf.

Please follow the details in the article to integrate with [Google OAuth](/docs/product/account-settings/authentication/google-oauth)

### Security Assertion Markup Language (SAML)

The Security Assertion Markup Language (SAML) stands as a critical protocol in the realm of secure authentication and authorization processes. Developed to enable Single Sign-On (SSO) functionality, SAML facilitates the exchange of authentication and authorization data between an identity provider (IdP) and a service provider (SP). This XML-based protocol ensures the secure transfer of user identity information, allowing individuals to access multiple applications and services with a single set of credentials. SAML operates on a trust model, wherein the identity provider asserts the user's identity to the service provider, which, in turn, grants or denies access based on the provided assertions.

Please follow the details in the article below to integrate with various popular SAML providers.

1. [Okta](/docs/product/account-settings/authentication/saml-sso/okta)
2. [Auth0](/docs/product/account-settings/authentication/saml-sso/auth0)
3. [Ping Identity](/docs/product/account-settings/authentication/saml-sso/ping-identity)
4. [Active Directory](/docs/product/account-settings/authentication/saml-sso/azure-ad)
5. [Keycloak](/docs/product/account-settings/authentication/saml-sso/keycloak)

### OpenID Connect (OIDC)

The OpenID Connect (OIDC) protocol is a modern authentication layer built on top of the OAuth 2.0 framework, designed to address user authentication and authorization challenges in web and mobile applications. OIDC provides a standardized and secure way for applications to verify the identity of end-users. Leveraging JSON Web Tokens (JWTs), OIDC enables the exchange of user identity information between the identity provider (IdP) and the Service provider, typically a web application.

Please follow the details in the article below to integrate with various popular OIDC providers.

1. [Okta](/docs/product/account-settings/authentication/oidc-sso/okta)
2. [Auth0](/docs/product/account-settings/authentication/oidc-sso/auth0)
3. [Ping Identity](/docs/product/account-settings/authentication/oidc-sso/ping-identity)
4. [Active Directory](/docs/product/account-settings/authentication/oidc-sso/azure-ad)

## Accessing the SSO Configuration Menu

The location of the **SSO configuration menu** varies depending on your plan.

* If you're on the **Business plan**, you can access SSO settings from the workspace **Settings** section.
* For **Enterprise plan** users, the SSO menu is available under the **Admin Panel**.

Please follow the steps relevant to your plan to locate and configure SSO.

### Business Plan

1. Click **Settings** in the workspace sidebar.
2. Open the **Single Sign-On (SSO)** tab.

Here, you can manage your SSO settings, including adding new identity providers and configuring existing ones.

<img alt="SSO Configuration" src={__img0} placeholder="blur" />

Alternatively, you can directly access the SSO configuration screen using the URL:
`https://app.nocodb.com/{workspaceId}/sso`

### Enterprise Plan

For users on the Enterprise plan, the SSO configuration menu is located in the **Account Settings**. This allows for more advanced SSO configurations and management options across the entire organization.

1. Click on the user icon in the bottom left corner of the NocoDB interface.
2. Select **Account Settings** from the menu.
3. Navigate to the **Single Sign-on (SSO)** tab.

<img alt="SSO Configuration" src={__img1} placeholder="blur" />
<img alt="SSO Configuration" src={__img2} placeholder="blur" />

Alternatively, you can directly access the SSO configuration screen using the URL:
`https://your-domain/#/account/authentication`

### Domain Verification

For **NocoDB Cloud** users (both Business and Enterprise plans), domain verification is required before configuring SSO providers. This ensures that only users with email addresses from your verified domain can access the workspace through SSO.

**Domain Verification Process:**

1. Access the domain verification section:

* **Business Plan**: Navigate to **Settings** > **Single Sign-On (SSO)** in the workspace sidebar, then use the **Domain** section
* **Enterprise Plan**: Navigate to **Account Settings** > **Authentication** > **Domain Verification**

2. Enter your domain (e.g., `example.com`)
3. Copy the TXT record provided by NocoDB
4. Add the TXT record to your domain’s DNS via your registrar/DNS provider.
5. Wait for DNS propagation (this may take a few minutes to several hours)
6. Click **Verify** button in NocoDB to confirm domain ownership

Once verified, only users with email addresses under your verified domain(s) will be able to sign in via SSO. For example, if you've verified `example.com`, only users with emails like `user@example.com` will be allowed to sign in through the SSO page.

<Callout type="info">
  **On-premise deployments**

   do not require domain verification. Configure SSO providers directly without DNS verification.
</Callout>

### Allow email & password sign-in alongside SSO

<Callout type="info">
  This setting is available on 

  **self-hosted (on-premise)**

   deployments only.
</Callout>

By default, once SSO is configured the email and password sign-in form is hidden on the sign-in page to enforce SSO. The **Allow email & password sign-in alongside SSO** setting (default **off**) controls this behaviour:

* **Off** (default): configuring SSO hides the email and password form, so users must sign in through the configured identity provider.
* **On**: the email and password sign-in form is shown together with the SSO option on the sign-in page.

This setting is managed from **Account Settings** > **Authentication**, under **General Settings**.

<Callout type="tip">
  Even when the email and password form is hidden (the default), you can reveal it on the sign-in page by double-clicking the NocoDB logo. This provides a fallback sign-in path, for example if the configured identity provider is temporarily unavailable.
</Callout>

## SCIM Provisioning

<Callout type="info">
  SCIM provisioning is available on the Enterprise plan, both self-hosted and on NocoDB Cloud.
</Callout>

SCIM (System for Cross-domain Identity Management) v2.0 enables automatic user and group provisioning from your identity provider to NocoDB. When configured alongside SSO, SCIM automates the full identity lifecycle — from onboarding (creating organization members) to offboarding (deactivating access) — without manual intervention.

SCIM is configured from the **Admin Panel** by the Org Admin. NocoDB supports SCIM provisioning with Okta and Azure AD (Entra ID). For a detailed overview of SCIM features and configuration, see the [SCIM Provisioning guide](/docs/product/account-settings/authentication/scim).

## Good to know

* Once SSO is enabled for a workspace, API access is restricted to tokens generated after signing in via the configured identity provider (IdP). Tokens created before SSO was enabled will no longer work for that workspace and must be regenerated through an SSO-authenticated session. [Know more](/docs/product/account-settings/api-tokens#api-token-access-with-sso-enabled-workspaces).

## Availability

* For SSO Access - please reach [**out to sales team**](https://cal.com/nocodb/sales)

---

## Related pages

- [Google OAuth](https://nocodb.com/docs/product/account-settings/authentication/google-oauth.md): Learn about different methods available for authentication with NocoDB.
- [Two-Factor Authentication ☁](https://nocodb.com/docs/product/account-settings/authentication/two-factor-authentication.md): Learn how to enable and manage two-factor authentication (2FA) for your NocoDB account.
- [SCIM](https://nocodb.com/docs/product/account-settings/authentication/scim.md): Learn how to configure SCIM v2.0 for automatic user and group provisioning in NocoDB.
- [SSO FAQs](https://nocodb.com/docs/product/account-settings/authentication/FAQs.md): Frequently asked questions about Single Sign-On (SSO) in NocoDB.
