Skip to content
Seal
Esc
↑↓navigate↵open⌘Jpreview
On this page

Enterprise SSO (SAML / OIDC)

Company login via SAML or OIDC for Seal workspaces

Enterprise SSO (SAML / OIDC)

DocuSign-class buyers expect company login (SEA-66). Seal uses Better Auth’s @better-auth/sso plugin — SAML 2.0 and OIDC, bound to a workspace, with optional enforce-SSO.

Enterprise plan flag sso in plan limits gates the product surface; the endpoints below are live when the API is deployed with the SSO plugin.

What you get

Capability How
Register IdP POST /api/auth/sso/register (org owner/admin session)
Domain verification Enabled — DNS TXT token via SSO plugin verify endpoints before first sign-in
SP metadata GET /api/auth/sso/saml2/sp/metadata?providerId=…
Sign-in POST /api/auth/sign-in/sso → IdP redirect → ACS
Org provisioning First SSO login joins the provider’s organization as member
Enforce SSO PATCH /api/organizations/{slug}/security with { "ssoEnforced": true }

Enforce SSO

When ssoEnforced is true on the organization metadata, session members who did not authenticate through that workspace’s SSO provider get 403 { "error": "sso_required" } on org-scoped session routes. Owners can still PATCH …/security to turn enforcement off (recovery path if the IdP is misconfigured). API tokens are machine credentials and are not subject to this gate.

Typical admin flow

  1. Create / select the Seal workspace (Better Auth organization).
  2. Register a SAML (or OIDC) provider with organizationId + email domain.
  3. Complete domain verification (DNS TXT) so domainVerified is true.
  4. Exchange SP metadata with your IdP (Okta / Entra / Google Workspace).
  5. Optionally set ssoEnforced: true after a successful test login.

Was this page helpful?