Set up SSO for your organization
Single sign-on lets members sign in with your identity provider instead of a DRC password. You set it up yourself from the organization settings, with no DRC support ticket required.
Before you start
You need an organization on the Team plan and Admin access to it. You also need the ability to register an application in your identity provider, which usually belongs to whoever administers Okta, Entra ID, Google Workspace, or your chosen OIDC provider.
Register DRC in your identity provider
- In your identity provider, create a new OIDC application for DRC.
- Use the callback URL shown in DRC's SSO settings as the authorized redirect URI.
- Copy the issuer, client ID, and client secret, plus the authorization endpoint if your provider exposes it separately.
Result: your identity provider is ready to answer DRC sign-in requests.
Add the connection in DRC
- Open the organization page and go to SSO settings.
- Create a connection with a name your members will recognize.
- Add at least one email domain your team uses, such as
yourcompany.com. SSO discovery matches a member to your organization by this domain, so it is required. - Paste the issuer, client ID, and client secret from your provider.
- Save the connection.
Result: DRC can redirect members on your domains to your identity provider for sign-in.
Sign in with SSO
- Open the DRC sign-in screen and choose the SSO option.
- Enter your work email address.
- Confirm the organization button that appears and continue to your provider.
- Approve the sign-in in your provider. DRC completes the session and opens your workspaces.
Result: you are signed in through your provider with no DRC password involved.
Operating notes
- A person still needs an invitation and a role in your organization before SSO grants access. SSO proves identity; membership grants access.
- Remove a connection when a team leaves or an identity provider is retired. Members on that domain lose SSO sign-in until a new connection is configured.
- Contact support if you need to verify provider or tenant-specific behavior during setup.