Verify your domain
1
Add the domain
As an org admin, open Integrations, then the SSO tab. Under Verified domains, enter
the domain, for example
example.com, and click Add domain. Tick Also cover its
subdomains if people sign in with addresses such as name@eu.example.com.2
Publish the TXT record
The domain’s row shows a Name and a Value. At your DNS provider, create a TXT record
with the name
_sreagent-challenge.example.com (enter only _sreagent-challenge if your
provider adds the domain for you) and the sreagent-verification=... value shown.3
Verify
Click Verify. New records can take up to an hour to appear. When it succeeds the badge reads
Verified.
Add the provider
1
Open Add Provider
On the SSO tab, click Add Provider and enter a Name, then choose the Provider
Type.
2
OIDC
Register an application in your identity provider with the Redirect URI shown in the OIDC
Setup Guide on the tab. Enter its Client ID, Client Secret and Discovery URL, the
base issuer URL.
3
SAML
Save the provider first, then reopen it with Edit to copy the ACS URL and Entity ID
into your identity provider. Paste back its IdP SSO URL, IdP Entity ID and IdP
Certificate (PEM).
4
Map roles
Set the Group attribute name and add Group → role mapping rows to give each group a
role. The highest matching role wins and is re-applied at every sign-in. Default role
controls what happens when no group matches. Leave it on Leave unchanged unless you want
sign-in to set roles. No sync can remove your organization’s last admin.
5
Enable
Save, then click Enable on the provider’s row.
Sign in with SSO
On the sign-in page, enter your organization slug under Sign in with SSO and click Continue. Your providers appear as buttons. To skip the slug, usehttps://sreagent.app/login?org=<your-org>, or give your identity provider’s portal the start URL that Edit shows for the provider.
People you disable or remove are refused at sign-in, whichever protocol they use.
If Verified domains is empty, the tab warns that nobody new can be created at sign-in until you verify one. Invited people and existing members are not affected, and your group mappings set roles at each sign-in.
Related
- Sign in and join your team: how people join without SSO.
- Manage people and roles: the roles your group mappings assign.
- Plan matrix: which plans include SSO.

