Single sign-on
With single sign-on (SSO), members of your organization sign in to VoisX through your own identity provider (IdP), such as Microsoft Entra ID, Okta or Google Workspace. You can then require SSO so that password sign-in stops for your domain.
VoisX supports SAML 2.0 and OpenID Connect (OIDC).
You need the organization Owner or Admin role to set up SSO.
Before you start
SSO matches people to your organization by their email domain. Verify your domain under Organization → Domains first.
Connect your identity provider
-
Open Organization → Security.
-
Under Connect an identity provider, choose the protocol. You can't change the protocol later without removing the connection and connecting again.
-
Fill in the details from your IdP:
OpenID Connect
Field Where to find it Client ID The application you registered in your IdP. Client secret The same application. It is stored securely and never shown again. To keep the current secret when you edit the connection, leave this blank. Authorization endpoint Your IdP's OIDC discovery document. Token endpoint Your IdP's OIDC discovery document. Userinfo endpoint Your IdP's OIDC discovery document. Issuer Your IdP's OIDC discovery document. SAML 2.0
Field Where to find it Single sign-on URL Your IdP's SAML metadata. Entity ID Your IdP's SAML metadata. Signing certificate Your IdP's signing certificate, base64-encoded DER. -
Click Create connection.
-
Click Enable SSO, then Test connection to check the configuration.
How members sign in
On the sign-in page at app.voisx.ai, a member enters their work email and clicks Login with SSO. VoisX finds your organization's connection from the email domain and sends them to your IdP.
Require SSO
Once the connection is enabled and tested, click Require SSO (with grace period).
- A grace period starts. The console shows the date it ends.
- Until then, members can still sign in with a password.
- When the grace period ends, password sign-in stops for your domain and members must use SSO.
Click Make optional to allow password sign-in again.
Keep the connection healthy
- For SAML, the console shows when your IdP's signing certificate expires and warns you before it does. Update the certificate in time to avoid failed sign-ins.
- Edit connection changes the IdP details.
- Disable SSO turns it off without deleting the configuration.
- Remove SSO deletes the connection. Members can then no longer sign in through SSO. This can't be undone.