Manage workspace identity and user provisioning
This page explains how to control who can join your Lovable workspace and how they log in, using your company's email domains and login systems. You can set up automatic ways for team members to join and ensure everyone uses your company's approved login method.
Workspace owners and admins need this when they want to manage how their team accesses Lovable and joins their workspace.
Do this, in order
- 1
Go to your workspace settings, then navigate to 'Access' and select the 'Identity' tab.
This is the central place to manage all settings related to how people authenticate and join your workspace.
- 2
Verify your company's email domains under 'Verified domains'.
Proving you own your company's email domains is necessary for all other identity and provisioning features.
- 3
Connect your company's single sign-on (SSO) system under 'SSO providers' if you want team members to log in using your company's existing credentials.
This allows users to log in with their company accounts (like Okta or Microsoft Entra ID) instead of creating new Lovable passwords.
- 4
Review the 'User provisioning' section to decide how new users with your company's email address automatically join the workspace.
You can choose to automatically add users when they log in via SSO, or when they sign up with a verified email, and assign them a default role.
- 5
If you have existing colleagues with Lovable accounts using your verified domain, use 'Add existing users' to bring them into your workspace in one go.
This saves you from manually inviting each existing team member after verifying your domain.
- 6
Consider enabling 'Enforce SSO' if you want all workspace members to be required to log in through your company's SSO system.
This enhances security by ensuring everyone uses your company's approved login method and session duration settings.
Paste this into your project
I need to manage how my team authenticates and joins our Lovable workspace. I want to set up automatic user provisioning and enforce SSO. Can you guide me through the steps to configure verified domains, SSO providers, user provisioning options (SSO login, verified email sign-up, adding existing users), and enforce SSO for our workspace?
Words decoded
- SSO
- Stands for Single Sign-On. It's a way for users to log in once to one system (like your company's main login portal) and then automatically gain access to multiple other applications (like Lovable) without needing to log in again for each one.
- Provisioning
- The process of automatically setting up user accounts and access rights for new team members in a system like Lovable, rather than having to manually invite each person.
- JIT role
- Stands for Just-in-Time role. This is a specific role (like 'editor' or 'viewer') that is automatically given to a user the very first time they log into Lovable through your company's SSO system.
- SCIM
- Stands for System for Cross-domain Identity Management. It's a standard way for your company's central identity system (where all user accounts are managed) to automatically create, update, and remove user accounts and their roles in other applications like Lovable.
- Domain lock
- A set of advanced settings, usually enabled by Lovable support, that ensures everyone using your company's email domain must log in through your company's SSO and can only work within your company's Lovable workspaces.
Where people get stuck
- Turning off a provisioning method (like SSO login or verified email sign-up) only stops new users from joining automatically; it does not remove existing members from your workspace.
- Deleting your last verified domain will automatically disable 'Enforce SSO' and 'Verified email sign-up'.
- Deleting your SSO provider will automatically disable 'Enforce SSO', remove SCIM provisioning, and disable 'Require SSO' and 'Block workspace creation' for your domain.
- If SCIM provisioning is active, 'Verified email sign-up' will be disabled because SCIM takes over managing user membership centrally.
- On the Business plan, you cannot self-serve toggle 'SSO Just-in-Time provisioning'; it's automatically enabled when an SSO provider is configured.
- Enabling 'Enforce SSO' automatically disables 'Require two-factor authentication' if both are present, as your SSO provider handles multi-factor authentication.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.