Set up single sign-on (SSO) so your team signs into Lavalier with your company's identity provider. Lavalier uses the SAML 2.0 standard, and SSO can only be set up by an account Owner. The same page also lets you provision users automatically with SCIM.
Before You Start
- Owner permissions in Lavalier (anyone else sees an "owner only" message).
- SSO enabled for your account. SSO is part of your plan—if you're an owner and don't see it in Settings, contact your Lavalier account team.
- A SAML 2.0-compatible identity provider (IdP) such as Okta or Microsoft Entra.
- Access to add a DNS TXT record for your email domain.
Step 1: Open SSO Settings
Go to Settings → SSO & Provisioning.
Step 2: Verify Your Email Domain
You need a verified domain before you can turn SSO on. Verified domains are how teammates get routed to SSO by their email address.
Under Verified domains, add your domain (e.g.,
acme.com). A Verify [domain] dialog opens automatically with the DNS TXT record you need to add.In the dialog, copy the Name / host and Value, then create a DNS TXT record with them at your DNS provider.
Once the record has propagated, click Verify in the dialog. If you closed it, click Set up DNS on the domain row to reopen it.
Step 3: Add Your IdP's Metadata
Open the setup dialog and choose one method:
Upload the metadata file (easiest): Click Upload metadata XML and select your IdP's metadata file. Lavalier auto-fills the fields for you.
Enter it manually: Under or enter manually, fill in:
- Your IdP's Entity ID
- Your IdP's Sign-On URL
- The IdP signing certificate (PEM)
Step 4: Give Your IdP Lavalier's Details
In the same dialog, open Service provider details and copy these into your IdP:
- Entity ID
- ACS URL
- Sign-in URL — set this as the app's sign-on URL in your IdP so members can launch Lavalier from their dashboard.
You can also download Lavalier's certificate (.pem) or the full metadata XML, which most IdPs accept directly.
Step 5: (Optional) Adjust Advanced Options
Expand Advanced SAML options only if you need to:
- Map non-standard attributes (Email, First name, Last name)
- Turn on Sign AuthnRequests (recommended)
- Turn on Require encrypted assertions
Most setups can leave these at their defaults.
Step 6: Test the Connection
Click Test SSO sign-in to confirm everything works end-to-end before you turn SSO on.
Note: The first time someone signs in through SSO, Lavalier creates their account automatically (just-in-time provisioning) with the Team Member role—no invitation email needed.
Step 7: Turn SSO On
Flip the Use single sign-on switch.
If an Enable SSO? warning appears, some people on your verified domains already have Lavalier accounts in another organization. Add them to your identity provider first, or they'll be locked out—then confirm.
Lavalier shows your recovery codes once. Save them immediately (see the next section).
How enforcement works:
- Everyone with an email on a verified domain must use SSO—including owners. There's no owner-bypass toggle.
- Users on unverified domains aren't affected. The page shows how many they are and confirms they won't be required to use SSO.
- You can't remove your last verified domain while SSO is on. Turn SSO off, or verify another domain first.
Step 8: Save Your Recovery Codes
Recovery codes let an owner sign in if your identity provider is ever unavailable.
When SSO is first enabled, Lavalier reveals a set of codes under Your recovery codes—shown once.
Save them now, ideally in a password manager. They can't be retrieved later.
Good to know:
- Each owner has their own set, and each code works once.
- Manage codes anytime with the Manage recovery codes link: Generate, Regenerate (revokes the old set), or Revoke all.
- Locked out? Open the recovery sign-in page, enter your email and a code, and open the emailed sign-in link within 15 minutes.
Provision Users Automatically (SCIM)
The SSO & Provisioning page also supports SCIM, which lets your identity provider create, update, and deactivate Lavalier users automatically.
- The SCIM section appears once you've set up SAML.
- The Enable SCIM toggle unlocks once SSO is on.
See Setting Up SCIM Provisioning for the full setup.
What Your Team Sees
Once SSO is enabled, teammates enter their work email on the login page and are routed to your identity provider to sign in. You can also share the direct /sso/<slug> link as a bookmark or an app tile in your IdP.
What's next?
- Inviting Users and Managing Permissions — Manage who has access and what they can do
- Setting Up Your Company OS — Configure the rest of your account settings
Troubleshooting
I don't see SSO & Provisioning in Settings
Solution: SSO is configured by account owners and must be enabled for your account. If you're an owner and still don't see it, contact your Lavalier account team to enable it.
I can't turn SSO on
Solution: You need at least one verified domain before you can enable SSO. Under Verified domains, add your domain and complete the DNS TXT verification, then try again.
A teammate sees "We couldn't complete SSO for this email"
Solution: The full message is "This can happen when your email is linked to multiple Lavalier accounts." It appears when someone's email is tied to more than one Lavalier account. They should contact their Lavalier admin or support@lavalier.ai for help signing in.
A teammate sees "Single sign-on isn't configured for that URL"
Solution: The /sso/<slug> address is wrong, or SSO isn't set up yet. Double-check the link matches the one in your SSO & Provisioning settings.
My identity provider is down and I can't sign in
Solution: Use a recovery code. Open the recovery sign-in page, enter your email and one of your recovery codes, and open the emailed sign-in link within 15 minutes. If you don't have codes, another owner with codes can sign in and help.
SSO stopped working after being fine
Solution: Your IdP's certificate may have expired. The SSO settings show an IdP signing certificate status that warns you as it nears expiry. Rotate the certificate in your identity provider, then upload the updated metadata in Lavalier.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article