SSO is available on the Team and Scale plans. See Billing to upgrade. Only owners and admins can configure SSO.
Setting up SSO
Go to SSO in your organization’s admin navigation to open the setup wizard. It walks through four steps, in order:1
Configure your OIDC provider
Enter your identity provider’s details:
Register Zespan as an OIDC application in your IdP first, using the redirect URI shown in your provider’s app configuration screen.
2
Verify domain ownership
Add the displayed DNS TXT record (
_zespan-verify.<your-domain>) at your DNS provider, then click Verify Domain. DNS changes can take up to 48 hours to propagate.3
Test the connection
Click Test SSO Login to run a real sign-in against your IdP in a popup window, without affecting any live sessions. Fix any configuration issues before moving on — you can’t enable SSO until a test succeeds.
4
Enable and, optionally, enforce
Click Enable to make SSO available to members with a matching email domain. They’ll see a Continue with SSO option on the sign-in page once they enter their work email.Turning on Enforce SSO blocks email/password and social login for everyone except the organization owner, who always keeps password access as a break-glass fallback. This is a deliberate step with its own confirmation dialog — double-check your test connection succeeded before enforcing.
How members sign in
On the sign-in page, a member enters their work email. If it matches your verified SSO domain, Zespan shows Continue with SSO, which redirects to your identity provider. After authenticating there, they’re returned to Zespan already signed in — no separate Zespan password is needed once SSO is enforced.Disabling or changing SSO
- Disable turns off SSO sign-in immediately; members fall back to email/password and social login.
- Remove enforcement un-blocks email/password and social login without disabling SSO itself.
- Updating the Issuer URL, Client ID, or domain takes effect immediately — re-run the connection test after any change to your IdP configuration.
Next steps
- Security — encryption, authentication, and data controls
- Organizations — roles and team management
- Billing — plans and upgrading to Team or Scale

