> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blitzy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On (SSO)

> Configure Enterprise Single Sign-On for your organization through domain verification and identity provider setup

Blitzy supports Enterprise Single Sign-On (SSO), allowing your organization to authenticate users through your existing Identity Provider (IdP) - Okta, Microsoft Entra ID, Google Workspace, or any other SAML-compatible provider.

<Note>
  **Jump to:** [Before You Begin](#before-you-begin) | [Domain Verification](#step-1-domain-verification) | [IdP Configuration](#step-2-identity-provider-idp-configuration) | [Troubleshooting](#troubleshooting)
</Note>

Setting up SSO requires two steps, typically performed by two different administrators:

| Step                                                                              | Who performs it             | What it involves                         |
| --------------------------------------------------------------------------------- | --------------------------- | ---------------------------------------- |
| [1. Domain Verification](#step-1-domain-verification)                             | DNS Administrator           | Adding a TXT record to your DNS settings |
| [2. Identity Provider Configuration](#step-2-identity-provider-idp-configuration) | Security / IT Administrator | Granting Blitzy access to your IdP       |

<Note>
  **Already signing in with Microsoft?** No immediate action is required. Continue signing in as usual. However, completing the SSO setup below provides stronger security and a more seamless login experience for your organization.
</Note>

## Before You Begin

* **Super Admin access** - Required in Blitzy to initiate the setup
* **DNS Administrator** - Needed for Step 1 to add a record to your domain's DNS settings. This is a minor, non-disruptive change.
* **Security or IT Administrator** - Needed for Step 2 to configure your Identity Provider

## Step 1: Domain Verification

Domain verification proves to Blitzy that your organization owns the domain used for employee email addresses (e.g., `yourcompany.com`). This is a one-time step performed by your DNS Administrator.

<Steps>
  <Step title="Open Authentication Settings">
    Navigate to **Settings** by clicking the **gear icon** in the top-right corner of your workspace. Select the **Authentication** tab.
  </Step>

  <Step title="Start Domain Verification">
    In the **Domain Verification** section, click **Verify**.

    <Note>This step should be performed by a Super Admin.</Note>

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-auth-settings.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=5a6cc7b2bdef0095e445e0b1f3b5d53e" alt="The Blitzy Settings page with the Authentication tab selected, showing the Domain Verification section and Verify button" width="1139" height="600" data-path="images/sso-auth-settings.png" />
    </Frame>
  </Step>

  <Step title="Enter Your Domain and Add the DNS Record">
    Enter your organization's domain. Blitzy generates a **TXT record** that your DNS Administrator must add to your domain's DNS settings.

    Provide this TXT record to your DNS Administrator. They will add it in your DNS provider's control panel (e.g., Cloudflare, Route 53, GoDaddy).

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-domain-entry.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=39e5e8a57c2732cba632ed6efc0b772e" alt="The domain entry prompt showing the organization domain field" width="837" height="582" data-path="images/sso-domain-entry.png" />
    </Frame>
  </Step>

  <Step title="Wait for Verification">
    DNS propagation can take up to **48 hours**. The verification process runs automatically in the background - no action is needed during this time.

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-dns-record.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=47f9da3ba9ee68844fa5408cebda246c" alt="The DNS record details and verification pending state" width="1377" height="756" data-path="images/sso-dns-record.png" />
    </Frame>
  </Step>

  <Step title="Confirm Verified Domain">
    Once validated, a success message appears. Return to the Blitzy platform to confirm the domain shows as verified.

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-domain-verified.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=4d6e189fd589f29941907431b4304248" alt="The Domain Verification success state confirming the domain has been verified" width="1381" height="757" data-path="images/sso-domain-verified.png" />
    </Frame>
  </Step>
</Steps>

## Step 2: Identity Provider (IdP) Configuration

Once your domain is verified, a Security or IT Administrator can connect your Identity Provider to enable SSO login for your organization.

<Steps>
  <Step title="Open the SSO Configuration">
    From the **Authentication** settings page, click **Configure** in the Single Sign-On section.

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-configure-button.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=6573a34fb7c2811b5e4e6ff44d29201d" alt="The Authentication settings page showing the Configure button for SSO setup" width="1388" height="749" data-path="images/sso-configure-button.png" />
    </Frame>
  </Step>

  <Step title="Select Your Identity Provider">
    Choose your organization's Identity Provider from the list. Supported providers include Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, and others.

    After selecting your provider, Blitzy displays setup instructions tailored to that specific IdP.

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-select-provider.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=0914bd8613b83e7174eb3b96d73021c6" alt="The Identity Provider selection screen showing available provider options" width="876" height="663" data-path="images/sso-select-provider.png" />
    </Frame>
  </Step>

  <Step title="Complete the IdP Setup">
    Follow the step-by-step instructions shown on screen. These instructions are specific to your chosen provider and walk you and your IdP administrator through all required configuration steps.

    <Tip>Keep Blitzy and your IdP's admin console open in separate browser tabs - you will be copying values between them.</Tip>

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-idp-setup-steps.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=1875d9db898666c520da554d11029741" alt="The step-by-step IdP configuration instructions for the selected provider" width="1050" height="725" data-path="images/sso-idp-setup-steps.png" />
    </Frame>
  </Step>

  <Step title="Test the Connection">
    After completing the configuration, use the **Test Connection** option to verify SSO is working correctly before rolling it out to your organization.

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-test-connection.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=4bcf4258b6ed350cc71b796b9fb7e8b7" alt="The Test Connection success screen at the end of the SSO setup flow" width="917" height="459" data-path="images/sso-test-connection.png" />
    </Frame>
  </Step>

  <Step title="Confirm SSO Status">
    Return to the **Authentication** settings page. The updated status confirms SSO is active.

    <Frame>
      <img src="https://mintcdn.com/blitzy-c2eefe5a/aSqbecWObkFpnh9C/images/sso-connected-status.png?fit=max&auto=format&n=aSqbecWObkFpnh9C&q=85&s=e53faccdeb28e96e72ebc4bb004efc1b" alt="The Authentication settings page showing the SSO connection as active" width="1069" height="513" data-path="images/sso-connected-status.png" />
    </Frame>
  </Step>
</Steps>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Domain verification is taking longer than expected">
    DNS propagation can take up to 48 hours depending on your DNS provider and TTL settings. If verification has not completed after 48 hours, confirm the TXT record was added correctly and contact [support@blitzy.com](mailto:support@blitzy.com).
  </Accordion>

  <Accordion title="Identity Provider not listed">
    Blitzy supports any SAML 2.0-compatible Identity Provider. If your provider is not listed, select **Custom SAML** and follow the instructions, or reach out to [support@blitzy.com](mailto:support@blitzy.com) for assistance.
  </Accordion>

  <Accordion title="SSO test is failing">
    Double-check that all values (ACS URL, Entity ID, etc.) were copied accurately between Blitzy and your IdP. Even a small typo causes the connection to fail. If the issue persists, contact your IdP administrator or reach out to Blitzy support.
  </Accordion>
</AccordionGroup>

### Getting Help

Contact [support@blitzy.com](mailto:support@blitzy.com) or reach out to your Blitzy account representative.

<CardGroup cols={2}>
  <Card title="Teams & Roles" icon="users" href="/administration/teams">
    Manage teams and member access
  </Card>

  <Card title="Environment Configuration" icon="server" href="/administration/environments">
    Configure environments for AI-Native development
  </Card>
</CardGroup>
