Single Sign-On (SSO) for team members
Team SSO lets your colleagues access the Frill dashboard through your existing identity provider instead of managing separate passwords. This centralizes access control and improves security.
Team SSO is available on Business plan and higher.
Supported authentication methods
Frill supports three team SSO options:
SAML 2.0: Enterprise standard protocol, ideal for Okta and similar identity providers
OIDC/OAuth 2.0: Modern authentication, used by Microsoft Entra ID (formerly Azure AD)
Token-based (JWT): Custom authentication where your server generates signed tokens
How team SSO works
When team SSO is enabled:
Team members navigate to your Frill workspace login
They're redirected to your identity provider
After authenticating there, they're automatically signed into Frill
No separate Frill password is required
Setting up team SSO
The setup process varies by provider. Generally:
Go to Settings > SSO in your Frill dashboard
Choose your authentication method (SAML, OIDC, or JWT)
Follow the provider-specific setup guide
Test the connection with a team member
Enable SSO for all team members
For detailed setup instructions, see:
Managing SSO access
Once SSO is enabled:
Add team members in your identity provider—they'll automatically have access to Frill
Remove users from your identity provider to revoke Frill access
Control role assignments in Frill's Settings > Company > Team
When SSO is enforced, team members cannot use password-based login. Make sure your identity provider is properly configured before enforcing SSO.
Team SSO vs. widget SSO
Team SSO is for internal colleagues accessing the dashboard. Widget SSO is for end-users interacting with your feedback boards. These work independently—you can enable one or both. See Single Sign-On (SSO) for widget users for widget SSO details.