> ## Documentation Index
> Fetch the complete documentation index at: https://docs.decimal.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On

> Require your team to sign in to Decimal through your identity provider, and keep members in sync with it.

Open [**Settings → General**](https://app.getdecimal.ai/settings/general) and click **Manage members**.

<img src="https://mintcdn.com/decimalai/43cMcK0ceVLqr4HK/images/sso-manage-members.png?fit=max&auto=format&n=43cMcK0ceVLqr4HK&q=85&s=de3a44e878e4481b1298e47a1efc4491" alt="The General settings page, with the Manage members button on the Members row" width="1982" height="948" data-path="images/sso-manage-members.png" />

## Set Up SSO

In the window that opens, pick **Security** in the sidebar, then click **Configure** under **SSO** and follow the steps for your identity provider.

<img src="https://mintcdn.com/decimalai/43cMcK0ceVLqr4HK/images/sso-security-tab.png?fit=max&auto=format&n=43cMcK0ceVLqr4HK&q=85&s=76df92979a4960c3ffab4cb82af418c9" alt="The Security tab, with Configure buttons for SSO and Directory Sync" width="2000" height="1678" data-path="images/sso-security-tab.png" />

Once it's on, anyone whose email matches your domain signs in through your identity provider.

You'll need admin access to your identity provider, and to your domain's DNS to add a `TXT` record that proves you own it.

## Supported Providers

* Okta Workforce
* Microsoft Entra ID
* Google Workspace
* Any other SAML provider
* Any OIDC provider

Clerk keeps the [up-to-date list](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/overview).

## Sync Members From Your Directory

**Directory Sync** keeps your Decimal members in sync with your identity provider. It works with any of the providers above that support SCIM 2.0. You can turn it on once SSO is set up.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.