Supported identity providers
Microsoft Entra ID
Sign in with Microsoft work accounts (formerly Azure AD).
Okta
Sign in with identities from your Okta organization.
Sign in with Google or Google Workspace accounts. Available with no setup.
How sign-in works
1
Enter a work email
The user opens Corsa, clicks Continue with SSO, and enters their work email. With Google, they click Continue with Google instead.
2
Corsa routes the user to your IdP
Corsa recognizes your email domain and redirects the user to your identity provider.
3
Your IdP authenticates the user
The user signs in under your organization’s policies, then returns to Corsa.
4
Corsa checks workspace access
Corsa matches the email to an invitation for your workspace and opens it with the invited role.
SSO controls how people sign in. Workspace invitations control who gets access. An IdP account that hasn’t been invited to your workspace cannot open it.
Setup at a glance
Microsoft Entra ID and Okta need a one-time setup. Google sign-in works without any setup.- Create an OIDC application in your identity provider, using the redirect URIs for your region.
- Send Corsa the application’s credentials and the email domains your users sign in with.
- Corsa connects your IdP to your workspace and lets you know when it’s live.
- Invite a test user, confirm they can sign in, then invite the rest of your team.
Redirect URIs by region
Sign-in uses the
auth0.com URI today. The auth.corsa.finance URI is Corsa’s branded sign-in domain. Registering both now means you won’t need to change anything when Corsa switches to it.
Users, roles, and security
- Invitations. A workspace owner invites each user by the exact email address their IdP returns. A matching invitation is accepted automatically on the user’s first SSO sign-in.
- Roles. Roles are assigned in Corsa, per invitation. Corsa doesn’t read IdP groups or app roles.
- Two-step verification. Corsa may also ask users to set up its own two-step verification on first sign-in, with an authenticator app, an email code, or a passkey. To rely on your IdP’s MFA only, contact your Corsa representative.
- Require SSO. Ask Corsa to require SSO for your workspace once your test sign-in succeeds. Your workspace then rejects every other sign-in method, such as email and password or Google, for all members.
- Offboarding. Disabling a user in your IdP stops their SSO sign-in. To remove their workspace access completely, also remove them from your Corsa workspace.