Skip to main content

Single sign-on (SSO) with your own identity provider

Let your team sign in to charles with your company's existing identity provider, such as Okta, Microsoft Entra ID or Google Workspace.

charles supports single sign-on. Your team signs in with the corporate credentials they already use, and your IT team keeps control of who has access.

Which providers work

Any identity provider that speaks SAML 2.0 or OIDC. That covers Okta, Microsoft Entra ID (Microsoft 365), Google Workspace, Ping, OneLogin, Keycloak and the rest.

What your IT team needs to do

Your IT team creates an application for charles in your identity provider and sends us the connection details:

For OIDC

  1. Client ID

  2. Client secret

  3. Issuer URL

For SAML 2.0

  1. The metadata XML from your provider (or the metadata URL)

We give your IT team the redirect and reply URLs to paste into that application, then we connect it on our side and test it with you before you roll it out.

The one requirement

Your identity provider has to send the same email address each person holds in charles. We match people on email, so [email protected] in your provider has to be [email protected] in charles. Mismatched addresses cannot sign in.

How signing in changes for your team

Your team opens the charles login page, enters their work email, and lands on your provider's sign-in screen. Once your provider confirms them, they come back to charles already signed in. Anyone already signed in to your provider that day goes straight through.

Password rules, MFA and session length come from your provider from that point on. Nobody needs a separate charles password.

💡 Not the same as Sign in with Google. That option lets one person use their own Google account. SSO covers your whole team through your company's provider.

What stays in charles

  • Adding people. Admins still invite users and set roles in charles.

  • Roles and permissions. Managed in charles, not in your provider.

  • Removing access. Disable someone in your provider and they can no longer sign in. Remove them in charles as well to free up their seat.

Getting started

Message your charles contact or reach out via the 💬 chat bubble. Tell us which provider you use and whether you want OIDC or SAML, and we will send your IT team the setup details.

🚨 Any trouble signing in? Reach out to our support team via the 💬 chat bubble, we're here to help!

Did this answer your question?