← Help centre

Single sign-on: set it up, sign in with it, take it away

Signed in? Ask Lovelio this question inside the app - it answers from this same page.

Single sign-on (SSO) lets people at your agency sign in with your company identity provider instead of a Lovelio password. Set it up at Settings > Integrations, on the Single Sign on tab. Only an admin can do this. For passwords and passkeys, see the account security card.

How to set up SSO

  1. Go to Settings > Integrations > Single Sign on.
  2. Under Add a new connection, type your Email domain (for example acme.com).
  3. Pick the Identity provider: Google Workspace, Microsoft Entra (Azure AD), or SAML 2.0 (Okta, JumpCloud, OneLogin and others). SAML 2.0 is the default.
  4. Click Create connection.
  5. A green box says "Connection created. Finish setup in the WorkOS Admin Portal." Click Open Admin Portal and follow the steps there to link your identity provider.
  6. Back on the page, the connection shows as Pending setup. Once your provider is verified, Lovelio marks it Active. If it stays on Pending setup, click Mark active on that row.

Only Active connections are used at sign-in.

How people sign in once it is on

  1. They go to the sign-in page and type their work email.
  2. If their domain has an active SSO connection, the page shows Continue with SSO. Passwords and other buttons are not offered for that domain.
  3. They sign in with your identity provider and land in Lovelio.

The email your provider sends back must match the connection's domain. If it does not, the sign-in is refused. The messages people may see:

  • "Your email domain is not set up for SSO. Ask your admin."
  • "Your SSO identity does not match this company."
  • "SSO is not configured on this environment."

What a new SSO user gets

The first time someone signs in with SSO, Lovelio creates their user and adds them to your agency with the default role, which is the least-privileged one. An admin can change it at Settings > Workspace > Users. Lovelio does not sync your directory (no SCIM), so people are added when they first sign in, not before.

How to read the Connections list

Each row shows the domain, a status (Active, Pending setup or Disabled), the provider, and Last sign-in once someone has used it.

  • Mark active on a Pending setup row switches it on.
  • The refresh icon (Open WorkOS Admin Portal) reopens the setup portal for that connection.
  • The bin icon (Remove connection) asks "Remove this SSO connection? Users will no longer be able to sign in via this IdP." Click Remove to confirm.

How to remove SSO

Click the bin icon on the connection, then Remove. People on that domain can no longer use that identity provider to sign in.

Why I cannot set it up

  • The Single Sign on tab is missing. You need the Integrations permission in Settings. Ask an admin.
  • "SSO needs an active paid subscription. Subscribe to enable it." SSO needs an active paid plan. The link on that message goes to Settings > Billing.
  • "SSO provider not configured". SSO is not switched on for this environment. An administrator has to set it up on the server side.
  • "Invalid domain." or "A valid domain is required." Use your company domain. Free email domains such as gmail.com are refused.
  • "Failed to create connection." That domain may already have a connection. Check the Connections list first.