Single Sign-On (SSO)

Single Sign-On (SSO)

Let your organization's users sign in to Kensho with your identity provider.

Guides

  • SAML 2.0: configure SAML SSO from your IdP.
  • OIDC: configure OIDC SSO from your IdP.

Provisioning

Kensho provisions accounts just-in-time (JIT): the first time one of your users signs in through SSO, Kensho creates their account from the attributes your IdP sends.

Kensho identifies each user by their email address. On every sign-in, the email your IdP sends is used to match the user to their Kensho account, so it must stay stable — if a user's email changes, they are treated as a new user.

Automatic account syncing and deprovisioning (SCIM) is not currently supported.