Files
twenty/packages/twenty-docs/user-guide/permissions-access/capabilities/sso-configuration.mdx
T
Rashad Karanouh b47e64c9e3 docs: surface the self-serve partner marketplace on high-intent pages (#22719)
## Summary

Adds partner-marketplace CTAs to four high-intent docs pages (enterprise
+ migration), routing readers to the **self-serve** partner directory
(`twenty.com/partners/list`) while keeping `contact@twenty.com` as a
secondary option. This upgrades pages that previously only offered the
old "email us to be matched" path (or no partner path at all).

Rendered with Mintlify-native components — `<Tip>` callouts, plus a
`<CardGroup>` on the Implementation Services page. No new snippet; no
`docs.json`, navigation, or translation (`l/`) changes.

## Pages changed — screenshots (one per page)

> Preview locally with `npx nx run twenty-docs:dev` (localhost:3000), or
use the Mintlify PR preview once it posts on this PR. Paths below are
under `docs.twenty.com`.

### 1. `/user-guide/permissions-access/capabilities/sso-configuration`
`<Tip>` callout → *Find a certified Twenty partner* (Solutioning),
`contact@twenty.com` as a secondary aside.

_screenshot:_
<img width="712" height="616" alt="Screenshot 2026-07-09 at 12 14 05"
src="https://github.com/user-attachments/assets/e6521634-7783-466f-bfae-a4a49f64d941"
/>


### 2.
`/user-guide/data-migration/how-tos/migrating-from-self-hosted-to-cloud`
`<Tip>` callout → *Get a certified Twenty partner* (Hosting), contact
fallback.

_screenshot:_
<img width="665" height="193" alt="Screenshot 2026-07-09 at 12 14 23"
src="https://github.com/user-attachments/assets/30ecb4d2-fb7e-4e0f-9355-491713290f90"
/>


### 3. `/user-guide/data-migration/how-tos/migrating-from-other-crms`
`<Tip>` callout → **Done for you** (partner) vs **Onboarding pack**
(Twenty team).

_screenshot:_
<img width="659" height="273" alt="Screenshot 2026-07-09 at 12 14 35"
src="https://github.com/user-attachments/assets/9cc5bb3e-c8be-4734-9e03-dc5b536eeeb7"
/>


### 4.
`/user-guide/getting-started/capabilities/implementation-services`
`<CardGroup>` → **Browse certified partners** / **Get matched by
Twenty**.

_screenshot:_
<img width="706" height="766" alt="Screenshot 2026-07-09 at 12 14 47"
src="https://github.com/user-attachments/assets/01b69197-0f47-46fe-a40e-92c11286827e"
/>


## Notes for reviewers

- Links deep-link the directory via `?categories=<scope>` (verified
live) and carry a `?ref=docs-*` tag.
- **Attribution caveat:** twenty.com's analytics (Cloudflare Web
Analytics) is path-based, so `?ref=` is not measurable yet.
- `contact@twenty.com` intentionally kept as a secondary option.
- `mintlify validate` passes.

Opened as a draft.


<!-- This is an auto-generated description by cubic. -->
<a
href="https://cubic.dev/pr/twentyhq/twenty/pull/22719?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>
<!-- End of auto-generated description by cubic. -->
2026-07-09 16:56:52 +02:00

110 lines
3.4 KiB
Plaintext

---
title: SSO Configuration
description: Configure Single Sign-On for secure enterprise authentication.
---
## About SSO
Single Sign-On (SSO) allows your team members to log into Twenty using your organization's identity provider. This provides:
- **Centralized access control**: Manage access from one place
- **Enhanced security**: Leverage your existing security policies
- **Better user experience**: One set of credentials for all tools
## Supported Providers
Twenty supports SSO with:
- **SAML 2.0**: Works with most enterprise identity providers
- **Google Workspace**: For organizations using Google
- **Microsoft Entra ID**: (formerly Azure AD) For Microsoft environments
## Setting Up SSO
### Prerequisites
- Organization plan (cloud and self-hosted workspaces)
- Admin access to your identity provider
- Admin access to Twenty workspace
<Note>
**For self-hosting users willing to set up SSO**, reach out to contact@twenty.com
</Note>
### Configuration Steps
#### 1. Access SSO Settings
1. Go to **Settings → Security**
2. Find the **SSO Configuration** section
3. Click **Configure SSO**
#### 2. Choose Your Provider
Select your identity provider from the list or choose "Custom SAML" for other providers.
#### 3. Configure Your Identity Provider
You'll need to configure your identity provider with:
- **Entity ID**: Provided by Twenty
- **ACS URL**: The callback URL for authentication
- **Certificate**: For secure communication
#### 4. Enter Provider Details in Twenty
- **SSO URL**: Login URL from your provider
- **Entity ID**: Your provider's identifier
- **Certificate**: X.509 certificate from your provider
#### 5. Test and Enable
1. Click **Test Configuration** to verify setup
2. Enable SSO when testing is successful
3. Configure user provisioning preferences
## User Provisioning
### Just-in-Time (JIT) Provisioning
- Users are created automatically on first login
- Assigned default role automatically
- No manual user creation needed
### Manual Provisioning
- Invite users before they can log in
- Pre-assign specific roles
- More control over who can access
## Managing SSO Users
### Role Assignment
SSO users can be assigned roles like regular users:
1. Go to **Settings → Members**
2. Find the user
3. Change their role as needed
### Access Revocation
To remove access for SSO users:
- Remove them from your identity provider, or
- Remove them from the Twenty workspace
## Best Practices
### Security
- **Require SSO**: Disable password login for SSO users
- **Regular audits**: Review access periodically
- **Strong IdP policies**: Enforce MFA at the identity provider
### User Management
- **Clear naming**: Use consistent naming from your directory
- **Group mapping**: Map IdP groups to Twenty roles (if available)
- **Offboarding process**: Include Twenty in your deprovisioning workflow
## Troubleshooting
### Common Issues
- **Certificate errors**: Ensure certificate hasn't expired
- **URL mismatches**: Verify ACS URL matches exactly
- **User not found**: Check JIT provisioning settings
### Getting Help
If you encounter issues, contact support with:
- Error messages received
- Identity provider being used
- Configuration details (without sensitive data)
<Tip>
Need SSO configured for your organization? [Find a certified Twenty partner](https://twenty.com/partners/list?categories=SOLUTIONING&ref=docs-sso) who specializes in SSO and identity setup. *(Prefer to loop in Twenty directly? [contact@twenty.com](mailto:contact@twenty.com).)*
</Tip>