> For the complete documentation index, see [llms.txt](https://docs.distro.so/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.distro.so/settings/sso.md).

# Set up SAML single sign-on

Admins configure SAML sign-in from **Settings → SAML SSO**. Coordinate the setup with your identity-provider administrator and Distro support.

## Prepare the connection

Gather the identity provider's entity ID, sign-in URL and certificate, plus the email domain your workspace intends to use. Use the Distro service-provider details shown in setup when configuring your provider.

Save the identity-provider configuration and review its status before enforcing SSO. Keep a supported admin recovery path available while testing.

## Verify the sign-in domain

1. Add the intended sign-in domain.
2. Select **Start domain check**.
3. Add the displayed TXT value at that domain's DNS provider.
4. Use **Check now**, or wait for a scheduled check.
5. Contact Distro support to complete the domain-trust step.

The check runs periodically for up to 72 hours. **Confirmed** means the DNS evidence was found. It does not independently activate trusted-domain access. The trusted status appears as **Verified by Distro** when the support step is complete.

## Test sign-in

Test with a member whose work email matches the intended domain. Confirm they reach the right workspace before relying on enforcement for the team.

Distro's setup uses its SAML configuration and support-assisted domain trust. There is no separate WorkOS Admin Portal to follow in this guide.

If sign-in fails, check domain, provider audience/entity ID, destination URL, certificate and the member's email mapping with your identity-provider admin.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.distro.so/settings/sso.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
