Lynkarr Support
Contact us Sign in

Support / Team and permissions

Setting up single sign-on

Point your identity provider at Lynkarr so it owns these accounts. Enterprise, over OpenID Connect.

What it does

Your identity provider decides who exists. Somebody who joins can sign in without being invited; somebody who leaves loses this the moment you disable them, along with everything else they had.

Any provider that speaks OpenID Connect works: Entra ID, Okta, Google Workspace, Auth0, JumpCloud, Keycloak and the rest.

Setting it up

  1. Open Settings and find Single sign-on. Copy the redirect address it shows you.
  2. In your provider, create a web application and paste that address in as an allowed redirect URI.
  3. Copy the issuer, the client ID and the client secret out of your provider.
  4. Paste all three into Settings and press Save. We read the rest of your provider’s configuration from the issuer, so there is nothing else to copy.
  5. Switch on “Offer single sign-on”, then test it: open a private window and sign in with your own address.
  6. Once it works, switch on “Require it” if you want passwords to stop.
Test before you require it. That order is the difference between a five-minute change and a locked-out company.

Who gets in, and as what

Only addresses at the domains you list. A provider can return any address it likes, and a company that lists none gets its own domain only — which is what stops single sign-on becoming a way into somebody else’s account here.

Somebody signing in for the first time is created automatically, with the role you chose. Never owner: that is not a role an identity provider gets to hand out.

If something breaks

Owners can always sign in with a password, even when single sign-on is required. That is deliberate: a provider that stops answering at four on a Friday should not be a company locked out of its own account waiting for us.

A refused sign-in says which check failed, and the reason is in your audit log.

If you leave the Enterprise plan

Sign-in keeps working — cutting it off would lock out everybody who has never had a password. What stops is the requirement: passwords work again until you are back on the plan.

Roles, and what each one can do →
Still stuck? Tell us what happened — we read every message. lynkarr.com