User Management

Single Sign-On (SSO) for team members

Team SSO lets your colleagues access the Frill dashboard through your existing identity provider instead of managing separate passwords. This centralizes access control and improves security.

Team SSO is available on Business plan and higher.

Supported authentication methods

Frill supports three team SSO options:

  • SAML 2.0: Enterprise standard protocol, ideal for Okta and similar identity providers

  • OIDC/OAuth 2.0: Modern authentication, used by Microsoft Entra ID (formerly Azure AD)

  • Token-based (JWT): Custom authentication where your server generates signed tokens

How team SSO works

When team SSO is enabled:

  1. Team members navigate to your Frill workspace login

  2. They're redirected to your identity provider

  3. After authenticating there, they're automatically signed into Frill

  4. No separate Frill password is required

Setting up team SSO

The setup process varies by provider. Generally:

  1. Go to Settings > SSO in your Frill dashboard

  2. Choose your authentication method (SAML, OIDC, or JWT)

  3. Follow the provider-specific setup guide

  4. Test the connection with a team member

  5. Enable SSO for all team members

For detailed setup instructions, see:

Managing SSO access

Once SSO is enabled:

  • Add team members in your identity provider—they'll automatically have access to Frill

  • Remove users from your identity provider to revoke Frill access

  • Control role assignments in Frill's Settings > Company > Team

When SSO is enforced, team members cannot use password-based login. Make sure your identity provider is properly configured before enforcing SSO.

Team SSO vs. widget SSO

Team SSO is for internal colleagues accessing the dashboard. Widget SSO is for end-users interacting with your feedback boards. These work independently—you can enable one or both. See Single Sign-On (SSO) for widget users for widget SSO details.

Was this helpful?