b47e64c9e3
## Summary Adds partner-marketplace CTAs to four high-intent docs pages (enterprise + migration), routing readers to the **self-serve** partner directory (`twenty.com/partners/list`) while keeping `contact@twenty.com` as a secondary option. This upgrades pages that previously only offered the old "email us to be matched" path (or no partner path at all). Rendered with Mintlify-native components — `<Tip>` callouts, plus a `<CardGroup>` on the Implementation Services page. No new snippet; no `docs.json`, navigation, or translation (`l/`) changes. ## Pages changed — screenshots (one per page) > Preview locally with `npx nx run twenty-docs:dev` (localhost:3000), or use the Mintlify PR preview once it posts on this PR. Paths below are under `docs.twenty.com`. ### 1. `/user-guide/permissions-access/capabilities/sso-configuration` `<Tip>` callout → *Find a certified Twenty partner* (Solutioning), `contact@twenty.com` as a secondary aside. _screenshot:_ <img width="712" height="616" alt="Screenshot 2026-07-09 at 12 14 05" src="https://github.com/user-attachments/assets/e6521634-7783-466f-bfae-a4a49f64d941" /> ### 2. `/user-guide/data-migration/how-tos/migrating-from-self-hosted-to-cloud` `<Tip>` callout → *Get a certified Twenty partner* (Hosting), contact fallback. _screenshot:_ <img width="665" height="193" alt="Screenshot 2026-07-09 at 12 14 23" src="https://github.com/user-attachments/assets/30ecb4d2-fb7e-4e0f-9355-491713290f90" /> ### 3. `/user-guide/data-migration/how-tos/migrating-from-other-crms` `<Tip>` callout → **Done for you** (partner) vs **Onboarding pack** (Twenty team). _screenshot:_ <img width="659" height="273" alt="Screenshot 2026-07-09 at 12 14 35" src="https://github.com/user-attachments/assets/9cc5bb3e-c8be-4734-9e03-dc5b536eeeb7" /> ### 4. `/user-guide/getting-started/capabilities/implementation-services` `<CardGroup>` → **Browse certified partners** / **Get matched by Twenty**. _screenshot:_ <img width="706" height="766" alt="Screenshot 2026-07-09 at 12 14 47" src="https://github.com/user-attachments/assets/01b69197-0f47-46fe-a40e-92c11286827e" /> ## Notes for reviewers - Links deep-link the directory via `?categories=<scope>` (verified live) and carry a `?ref=docs-*` tag. - **Attribution caveat:** twenty.com's analytics (Cloudflare Web Analytics) is path-based, so `?ref=` is not measurable yet. - `contact@twenty.com` intentionally kept as a secondary option. - `mintlify validate` passes. Opened as a draft. <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/twentyhq/twenty/pull/22719?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. -->
110 lines
3.4 KiB
Plaintext
110 lines
3.4 KiB
Plaintext
---
|
|
title: SSO Configuration
|
|
description: Configure Single Sign-On for secure enterprise authentication.
|
|
---
|
|
|
|
## About SSO
|
|
|
|
Single Sign-On (SSO) allows your team members to log into Twenty using your organization's identity provider. This provides:
|
|
- **Centralized access control**: Manage access from one place
|
|
- **Enhanced security**: Leverage your existing security policies
|
|
- **Better user experience**: One set of credentials for all tools
|
|
|
|
## Supported Providers
|
|
|
|
Twenty supports SSO with:
|
|
- **SAML 2.0**: Works with most enterprise identity providers
|
|
- **Google Workspace**: For organizations using Google
|
|
- **Microsoft Entra ID**: (formerly Azure AD) For Microsoft environments
|
|
|
|
## Setting Up SSO
|
|
|
|
### Prerequisites
|
|
- Organization plan (cloud and self-hosted workspaces)
|
|
- Admin access to your identity provider
|
|
- Admin access to Twenty workspace
|
|
|
|
<Note>
|
|
**For self-hosting users willing to set up SSO**, reach out to contact@twenty.com
|
|
</Note>
|
|
|
|
### Configuration Steps
|
|
|
|
#### 1. Access SSO Settings
|
|
1. Go to **Settings → Security**
|
|
2. Find the **SSO Configuration** section
|
|
3. Click **Configure SSO**
|
|
|
|
#### 2. Choose Your Provider
|
|
Select your identity provider from the list or choose "Custom SAML" for other providers.
|
|
|
|
#### 3. Configure Your Identity Provider
|
|
You'll need to configure your identity provider with:
|
|
- **Entity ID**: Provided by Twenty
|
|
- **ACS URL**: The callback URL for authentication
|
|
- **Certificate**: For secure communication
|
|
|
|
#### 4. Enter Provider Details in Twenty
|
|
- **SSO URL**: Login URL from your provider
|
|
- **Entity ID**: Your provider's identifier
|
|
- **Certificate**: X.509 certificate from your provider
|
|
|
|
#### 5. Test and Enable
|
|
1. Click **Test Configuration** to verify setup
|
|
2. Enable SSO when testing is successful
|
|
3. Configure user provisioning preferences
|
|
|
|
## User Provisioning
|
|
|
|
### Just-in-Time (JIT) Provisioning
|
|
- Users are created automatically on first login
|
|
- Assigned default role automatically
|
|
- No manual user creation needed
|
|
|
|
### Manual Provisioning
|
|
- Invite users before they can log in
|
|
- Pre-assign specific roles
|
|
- More control over who can access
|
|
|
|
## Managing SSO Users
|
|
|
|
### Role Assignment
|
|
SSO users can be assigned roles like regular users:
|
|
1. Go to **Settings → Members**
|
|
2. Find the user
|
|
3. Change their role as needed
|
|
|
|
### Access Revocation
|
|
To remove access for SSO users:
|
|
- Remove them from your identity provider, or
|
|
- Remove them from the Twenty workspace
|
|
|
|
## Best Practices
|
|
|
|
### Security
|
|
- **Require SSO**: Disable password login for SSO users
|
|
- **Regular audits**: Review access periodically
|
|
- **Strong IdP policies**: Enforce MFA at the identity provider
|
|
|
|
### User Management
|
|
- **Clear naming**: Use consistent naming from your directory
|
|
- **Group mapping**: Map IdP groups to Twenty roles (if available)
|
|
- **Offboarding process**: Include Twenty in your deprovisioning workflow
|
|
|
|
## Troubleshooting
|
|
|
|
### Common Issues
|
|
- **Certificate errors**: Ensure certificate hasn't expired
|
|
- **URL mismatches**: Verify ACS URL matches exactly
|
|
- **User not found**: Check JIT provisioning settings
|
|
|
|
### Getting Help
|
|
If you encounter issues, contact support with:
|
|
- Error messages received
|
|
- Identity provider being used
|
|
- Configuration details (without sensitive data)
|
|
|
|
<Tip>
|
|
Need SSO configured for your organization? [Find a certified Twenty partner](https://twenty.com/partners/list?categories=SOLUTIONING&ref=docs-sso) who specializes in SSO and identity setup. *(Prefer to loop in Twenty directly? [contact@twenty.com](mailto:contact@twenty.com).)*
|
|
</Tip>
|