SSO / SAML Authentication

Enable Single Sign-On with your identity provider.

SSO / SAML Authentication

Enterprise Plan Feature

Enable Single Sign-On so your team can log in with their corporate identity provider (IdP).

Supported Providers

Setup

  1. Go to Settings → Security → SSO
  2. Click "Configure SSO"
  3. Enter your IdP details:
  1. Copy LemWatch's ACS URL and Entity ID into your IdP
  2. Test the connection
  3. Enable SSO enforcement (optional — require all team members to use SSO)

How It Works

SSO Enforcement

When enabled, all team members must use SSO — password login is disabled. The organisation owner always retains password access as a fallback.

SCIM Provisioning (Coming Soon)

Automatic user provisioning and de-provisioning via SCIM protocol.