Kordin Neo
Organization Acme Labs
Search or jump to ⌘K
$21.05
A bell with a count and a short list of what needs attention is not in this build yet. Documentation Get help Signed in as Sam Okonkwo Your settings
Enforcing single sign-on can lock everybody out, so the screen has to be specific about who still has a way in.

Single sign-on

single sign-on — SAML is deferred under V1-015 (forge 22:26)

For Acme Labs

OIDC and sessions exist as packages in forge, and nothing stores a per-org sign-in configuration or enforces one. PLATFORM_AUTH_ENABLED also defaults false

Identity provider
Where your people already sign in
Okta ▾
Metadata URL
From your provider's application settings. If what it gives you is SAML, see below — it still works, and not directly.
Email domain
People with an email here are sent to your provider to sign in
verified 12 August
Require it
Passwords stop working for everyone except Owners
SAML works through a translator, not directly. The product itself speaks one protocol, deliberately: two would mean two sets of security decisions to keep right forever, and the second set is where the mistakes live. A SAML directory is converted by something sitting in front, which is the translator is planned and not built, so a SAML-only directory is served after it exists rather than before — worth knowing now if SAML is all your directory offers, because it changes when you can turn this on rather than whether.
Owners keep a password, and that is the point. If Okta stops answering — a certificate runs out, somebody deletes the application — requiring it would otherwise lock every single person out of the org with no way back in. Two Owners with passwords is the difference between an outage and a support ticket.
Save

Single sign-on

single sign-on — SAML is deferred under V1-015 (forge 22:26)

For Acme Labs

Single sign-on is part of Scale which plan carries single sign-on is not yet in forge's capability list, and this org is on Base. Everyone signs in with an email and a password today, which works and is not going to stop.

It is worth having when the answer to “who can get into this” needs to live in one place rather than in this portal — usually the same moment somebody asks about roles.

you can fix this

This feature is not included in the current entitlement. Ask the account owner to enable it.

Reference 99d07cd5cb21Get help ›
Show the code CAPABILITY_NOT_GRANTED