Set up workspace single sign-on (SSO)
You can set up Single Sign-On (SSO) for your Lovable workspace so your team can log in using their company credentials from providers like Okta or Auth0. This makes logging in easier and more secure for everyone in your workspace.
Workspace owners or admins who want their team to use their company's login system for Lovable.
Do this, in order
- 1
Make sure you have admin access to your company's identity provider (like Okta or Auth0) and are a workspace owner or admin in Lovable.
These roles are necessary to configure SSO settings in both systems.
- 2
Verify your company's domain in Lovable.
Lovable requires a verified domain to prove ownership before you can set up SSO.
- 3
Go to 'Workspace settings' > 'Access' > 'Identity' in Lovable and click 'Add provider' in the 'SSO providers' section.
This is where you initiate the SSO setup process within Lovable.
- 4
Choose either 'Configure OIDC' or 'Configure SAML' based on your company's identity provider.
Lovable supports both OpenID Connect (OIDC) and SAML 2.0 protocols for SSO.
- 5
Follow the instructions on the Lovable screen to copy Lovable's URLs and settings into your identity provider's application configuration.
This links Lovable to your company's login system.
- 6
Copy your identity provider's issuer, metadata, or client credentials back into Lovable.
This completes the connection, allowing Lovable to trust your identity provider for logins.
- 7
Test the configuration in Lovable (for OIDC) or review the settings (for SAML) and then confirm to enable SSO.
Testing ensures the connection works correctly before fully enabling it for your workspace.
- 8
Consider enabling 'Enforce SSO' in 'Workspace settings' > 'Access' > 'Identity' after waiting 6 hours and testing SSO login.
This makes sure all members must use SSO to access the workspace, enhancing security and centralizing access management.
Paste this into your project
I need to set up Single Sign-On (SSO) for my Lovable workspace using my company's identity provider. I am a workspace owner/admin and have admin access to my IdP. My domain is already verified. Please guide me through the steps to connect my IdP to Lovable, including where to find the settings in Lovable and what information I'll need to exchange between Lovable and my IdP. I want to ensure my team can log in securely using their company credentials.
Words decoded
- SSO (Single Sign-On)
- A system that lets you log in once with one set of credentials and access multiple different applications without needing to log in again for each one.
- Identity Provider (IdP)
- The service that stores and manages your user identities and authenticates users. Examples include Okta, Auth0, or Microsoft Entra ID.
- OIDC (OpenID Connect)
- A modern standard for verifying who you are, built on top of another standard called OAuth 2.0. It's often used for web and mobile applications.
- SAML (Security Assertion Markup Language)
- An older, XML-based standard for securely exchanging authentication and authorization information between different services, commonly used in business settings.
- Verified Domain
- A company's internet address (like 'yourcompany.com') that you've proven you own or control to Lovable, usually by adding a special record to your domain's settings.
- ACS URL (Assertion Consumer Service URL)
- The specific web address where your identity provider sends the login information back to Lovable after a user successfully logs in.
- Entity ID / Audience URI
- A unique identifier for Lovable that your identity provider uses to know which service the login information is intended for.
- IdP-initiated SSO
- When a user starts their login process from their company's identity provider dashboard (e.g., clicking an app icon in Okta) to access Lovable.
- SP-initiated login
- When a user starts their login process directly from Lovable and is then redirected to their company's identity provider to complete authentication.
- Just-in-Time (JIT) provisioning
- A feature where user accounts are automatically created in Lovable the very first time someone logs in using SSO, rather than needing to be set up beforehand.
- SCIM (System for Cross-domain Identity Management)
- A standard for automating the creation, updating, and deletion of user accounts across different applications, managed centrally from your identity provider.
Where people get stuck
- Attempting to log in with SSO before linking an existing account will result in an error. Log in with your original method first to link accounts.
- The 'Forgot password?' feature does not work for accounts that log in through SSO. Users must reset credentials with their identity provider.
- A Lovable workspace can only have one active SSO provider configured at a time.
- If you enable 'Enforce SSO', invite links will only work for people whose email is on one of your verified domains.
- Enabling 'Enforce SSO' automatically disables 'Require two-factor authentication' in Lovable, as your identity provider becomes responsible for multi-factor authentication.
- For SAML, the Lovable catalog app in Okta does not support IdP-initiated login; users must start login from Lovable.
- If IdP-initiated login shows an error, ensure your email domain is verified in only one Lovable workspace. If issues persist, change the ACS URL in your IdP app back to the default Lovable handler URL.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.