> ## Documentation Index
> Fetch the complete documentation index at: https://docs.corsa.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on (SSO)

> Let your team sign in to Corsa with your identity provider, such as Microsoft Entra ID or Okta, while you keep control of who can access your workspace.

Single sign-on lets your team sign in to Corsa with the work accounts they already use. Your identity provider (IdP) enforces your own policies, such as MFA, conditional access, and offboarding. Corsa connects to your IdP over OpenID Connect (OIDC).

## Supported identity providers

<CardGroup cols={2}>
  <Card title="Microsoft Entra ID" icon="microsoft" href="/security/sso/microsoft-entra-id">
    Sign in with Microsoft work accounts (formerly Azure AD).
  </Card>

  <Card title="Okta" icon="key" href="/security/sso/okta">
    Sign in with identities from your Okta organization.
  </Card>

  <Card title="Google" icon="google" href="/security/sso/google">
    Sign in with Google or Google Workspace accounts. Available with no setup.
  </Card>
</CardGroup>

Using a different OIDC provider? Contact [support@corsa.finance](mailto:support@corsa.finance).

***

## How sign-in works

<Steps>
  <Step title="Enter a work email">
    The user opens Corsa, clicks **Continue with SSO**, and enters their work email. With Google, they click **Continue with Google** instead.
  </Step>

  <Step title="Corsa routes the user to your IdP">
    Corsa recognizes your email domain and redirects the user to your identity provider.
  </Step>

  <Step title="Your IdP authenticates the user">
    The user signs in under your organization's policies, then returns to Corsa.
  </Step>

  <Step title="Corsa checks workspace access">
    Corsa matches the email to an invitation for your workspace and opens it with the invited role.
  </Step>
</Steps>

<Info>
  SSO controls **how** people sign in. Workspace invitations control **who** gets access. An IdP account that hasn't been invited to your workspace cannot open it.
</Info>

***

## Setup at a glance

Microsoft Entra ID and Okta need a one-time setup. Google sign-in works without any setup.

1. Create an OIDC application in your identity provider, using the redirect URIs for your region.
2. Send Corsa the application's credentials and the email domains your users sign in with.
3. Corsa connects your IdP to your workspace and lets you know when it's live.
4. Invite a test user, confirm they can sign in, then invite the rest of your team.

### Redirect URIs by region

| Region | Corsa app | Redirect URIs |
| - | - | - |
| US | `app.corsa.finance` | `https://tweed-compliance.us.auth0.com/login/callback` and `https://auth.corsa.finance/login/callback` |
| EU | `app.eu.corsa.finance` | `https://tweed-compliance.eu.auth0.com/login/callback` and `https://auth.eu.corsa.finance/login/callback` |

Sign-in uses the `auth0.com` URI today. The `auth.corsa.finance` URI is Corsa's branded sign-in domain. Registering both now means you won't need to change anything when Corsa switches to it.

***

## Users, roles, and security

* **Invitations.** A workspace owner invites each user by the exact email address their IdP returns. A matching invitation is accepted automatically on the user's first SSO sign-in.
* **Roles.** Roles are assigned in Corsa, per invitation. Corsa doesn't read IdP groups or app roles.
* **Two-step verification.** Corsa may also ask users to set up its own two-step verification on first sign-in, with an authenticator app, an email code, or a passkey. To rely on your IdP's MFA only, contact your Corsa representative.
* **Require SSO.** Ask Corsa to require SSO for your workspace once your test sign-in succeeds. Your workspace then rejects every other sign-in method, such as email and password or Google, for all members.
* **Offboarding.** Disabling a user in your IdP stops their SSO sign-in. To remove their workspace access completely, also remove them from your Corsa workspace.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.