> ## Documentation Index
> Fetch the complete documentation index at: https://docs.caplena.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On (SSO)

> Set up Single Sign-On (SSO) for your organization using SAML 2.0.

Give your team one less password to remember. With SSO, your employees log in to Caplena using the same credentials they already use for everything else — and when someone leaves the company, revoking their access is as simple as removing them from your identity provider.

<Tip>
  Already use SSO for other tools? Your IT team likely already has the metadata file we need, so there's no new setup required on your end.
</Tip>

## What's supported

* **SAML 2.0** – Caplena supports SSO via the SAML 2.0 protocol.
* **Just-in-time (JIT) provisioning** – New users are created automatically the first time they log in via SSO, so there's no need to manually add accounts in advance.
* **Broad identity provider support** – Caplena works with all common identity providers, including Microsoft Entra ID, Google Identity, Okta, and others.

## Setting up SSO

To get started, reach out to our team at [support@caplena.com](mailto:support@caplena.com). We'll provide you with the SAML 2.0 metadata your IT team needs to configure the connection on your identity provider.

Most setups take just a few business days once we receive your metadata.

## FAQ

<AccordionGroup>
  <Accordion title="Do I need to create user accounts in advance?">
    No. With JIT provisioning enabled, accounts are created automatically the first time someone logs in through SSO.
  </Accordion>

  <Accordion title="Which identity providers are supported?">
    Any identity provider that supports SAML 2.0, including Microsoft Entra ID, Google Identity, and Okta.
  </Accordion>

  <Accordion title="Who do I contact to set this up?">
    Email [support@caplena.com](mailto:support@caplena.com) and our team will guide you through the setup.
  </Accordion>
</AccordionGroup>
