Set up single sign-on

Last updated: October 11, 2026

Let your team sign in to Layer through your company's identity provider, such as Okta, Microsoft Entra ID or Google Workspace, so who can sign in is managed in one place with the rest of your company's apps.

Before you start

  • Your workspace is on the Enterprise plan. On other plans the SSO connections section is locked behind Upgrade to Enterprise; select Contact Sales to enable it.
  • You have a Layer role that can open Workspace Settings, such as Admin.
  • You can add a TXT record to your company's DNS, or know who can.
  • You are an administrator in your identity provider who can create applications or connections there.

In Layer

  1. Click your workspace name at the bottom left of the sidebar, choose Workspace Settings, then select Security.

  2. Under Email domains, select Add domain, enter the domain your team's email addresses use (for example yourstudio.com), and select Add domain. The domain appears with the status Pending, and a Record name and Record value below it.

  3. Add a TXT record to your domain's DNS with that record name and value (use the copy buttons beside each), then select Verify. When Layer finds the record, the status changes to Verified.

  4. Under SSO connections, select Add connection and enter a Display name, for example the name of your identity provider.

  5. Select Continue to setup. A setup link opens in a new tab with step-by-step instructions for connecting your identity provider. Keep the Layer tab open. If the new tab did not open, select Reopen setup link.

  6. Select Done. The connection is listed with the status Setup incomplete until you finish the steps in your identity provider.

In your identity provider

The setup link opens a hosted setup guide from Auth0, the service Layer uses for sign-in. The link belongs to this one connection. If you need it again later, use Resume setup (below) rather than adding a second connection.

  1. Follow the guide in the new tab. It asks which identity provider you use and walks you through creating the application or connection on that provider's side, then collects the details Layer needs from it.

  2. Create the application in your identity provider as the guide describes, and assign the people or groups who should be able to sign in to Layer.

  3. Finish the last step of the guide. You can close the tab afterwards.

Lost the tab before you finished? Back on the Security page, open the ⋯ menu on the connection's row and select Resume setup. Layer creates a fresh setup link and opens it.

Check that it works

  1. Wait for the connection's status to change from Setup incomplete to Active. Layer checks for you in the background and the page updates on its own, so there is nothing to select. The Type column then shows the kind of provider you connected.

  2. In a private browser window, sign in to Layer as a test user with an email address at your verified domain, and confirm you are sent through your identity provider and land in the workspace.

  3. When sign-in works, decide how strict to be. Under Login methods, turn off Email & password and the other methods you no longer want, so members have to use SSO. Layer asks you to confirm before turning off Email & password. Do this only after at least one admin has signed in through SSO successfully, so nobody is locked out.

  4. Optionally, set an Auto-join role on the verified domain so new people from your company join the workspace automatically with that role, and turn off Self-signup if they should only join by invitation.

  5. To create and remove Layer accounts from your directory automatically, set up User provisioning (SCIM) on the same page. See Set up user provisioning with SCIM.

If something goes wrong

  • "We couldn't find the record yet." DNS changes can take a while to reach everyone. Check the record name and value match exactly, and try Verify again later. Layer also keeps checking in the background for several days; if it never finds the record, the domain shows Failed. Remove it from the row's ⋯ menu and add it again.
  • The connection stays at Setup incomplete. The steps in your identity provider are not finished. Select Resume setup from the row's ⋯ menu and complete the guide.
  • The connection shows Failed. Setup was not finished in time, or did not complete. Select Reconfigure from the row's ⋯ menu to open a new setup link and try again. Use the same option later to change the identity provider settings on an active connection.
  • "You cannot disable the login method you are currently using". You are signed in with the method you tried to turn off. Sign out, sign back in through SSO, then turn it off.

Related