> ## Documentation Index
> Fetch the complete documentation index at: https://docs.interchange.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On (SSO)

> Configure SSO to let your organization members sign in with their corporate credentials

Single Sign-On (SSO) lets members of your organization authenticate with your corporate identity provider (Okta, Azure AD, Google Workspace, and others) instead of managing a separate password.

<Info>
  SSO is configured by an **Admin** on your account. If you don't have that
  role, ask an admin to follow this guide.
</Info>

## Before you start

* Confirm you have an **Admin** role on the Scope3 account where you want to enable SSO.
* Have a member of the team with access to your identity provider's admin console available — completing setup requires either its SAML metadata URL or XML.
* Use a **corporate email address** as your Scope3 sign-in. Public domains (gmail.com, yahoo.com, etc.) are not supported.

## Setting up SSO

### Step 1 — Sign in to interchange.io

Sign in at [interchange.io](https://interchange.io) with your Admin account.

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/01-sign-in.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=73a78b93a81b44d2b55d6f9041644805" alt="Sign in to interchange.io" width="2936" height="1828" data-path="images/sso-setup/01-sign-in.png" />

### Step 2 — Open Account configuration on the homepage

From the homepage, find the **Admin** section and select **Account configuration**.

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/02-account-configuration.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=66475a68c7ffccc08eb521a45662145e" alt="Account configuration tile on the homepage" width="1920" height="526" data-path="images/sso-setup/02-account-configuration.png" />

### Step 3 — Register your company domain

Ensure your company domain has been registered and verified.

<Warning>
  You must complete **company domain registration** before SSO setup unlocks.
  The **Open setup portal** button stays disabled until your registered company
  domain is verified.
</Warning>

In the **Registered company domain** section, enter your company domain and click **Save**:

* If the domain matches your sign-in email (e.g., signed in as `you@acme.com` registering `acme.com`), it's **auto-verified** immediately.
* If it doesn't match (or for an account under an organization whose domain differs), the row goes to **Pending Scope3 approval**.

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/03-domain-required.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=076afee6cf4178fb962bc9382c9fa919" alt="SSO blocked until company domain is verified" width="2938" height="1316" data-path="images/sso-setup/03-domain-required.png" />

### Step 4 — Confirm the domain is Verified

Once the domain shows the **Verified** chip, the SSO section unlocks and the **Open setup portal** button becomes clickable.

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/04-domain-verified.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=8879c372a699adcc3666e623f41f4c62" alt="Account configuration with the registered company domain verified" width="2940" height="1146" data-path="images/sso-setup/04-domain-verified.png" />

### Step 5 — Review the Single Sign-On (SSO) section

In the **Single Sign-On (SSO)** section below the domain section you'll see setup instructions and an **Open setup portal** button.

<Note>
  You'll need a member of the team with access to your identity provider's admin
  console to complete the next step.
</Note>

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/05-sso-instructions.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=6c39e6944ea4f45e0830f6a5f5eb13d5" alt="Single Sign-On instructions on the Account configuration page" width="2926" height="570" data-path="images/sso-setup/05-sso-instructions.png" />

### Step 6 — Follow the steps in the setup portal

Click **Open setup portal**. A guided portal opens in a new tab and walks you through three sub-steps.

<Warning>
  Portal links expire **5 minutes** after generation. If your link expires,
  return to **Account configuration** and click **Open setup portal** again to
  generate a new one.
</Warning>

#### 6a — Select your identity provider

Pick your identity provider from the list (Okta, Azure AD, Google Workspace, and others).

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/06a-select-idp.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=679e49c99fedd3728916c23afaa23517" alt="Select identity provider in the SSO setup portal" width="2932" height="1818" data-path="images/sso-setup/06a-select-idp.png" />

#### 6b — Follow the configuration steps

Work through every step the portal presents — uploading SAML metadata, mapping attributes, and any provider-specific configuration.

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/06b-follow-steps.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=e9851a47133cca7012d199c3d79a232b" alt="Configuration steps in the SSO setup portal" width="2930" height="1628" data-path="images/sso-setup/06b-follow-steps.png" />

#### 6c — Test Single Sign-On

Once you've completed every step, the final step lets you **Test Single Sign-On**. If the test doesn't pass, please reach out to Scope3 for support.

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/06c-test-sso.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=d671b37ab7c934018713369db09c667f" alt="Test Single Sign-On step in the setup portal" width="2934" height="864" data-path="images/sso-setup/06c-test-sso.png" />

### Step 7 — Your team can now sign in with SSO

Once the test passes, members of your organization can sign in to interchange.io with their corporate credentials.

<img src="https://mintcdn.com/agentic2/qyQtDrxhXnQLYZ8s/images/sso-setup/07-sso-active.png?fit=max&auto=format&n=qyQtDrxhXnQLYZ8s&q=85&s=ef5d7344e93ef5b49a0845830897d478" alt="SSO active confirmation on the Account configuration page" width="2936" height="1828" data-path="images/sso-setup/07-sso-active.png" />

## Updating SSO configuration

After SSO is active, you can update or replace your identity provider connection at any time by returning to **Account configuration → Single Sign-On (SSO)** and clicking **Open setup portal** again.

## Troubleshooting a timeout

If Google Workspace, Okta, or another provider appears to time out, retry once
in a fresh browser session. If the failure happened in the setup portal, return
to **Account configuration** and open a new portal link. If it happened during
sign-in, start again from the Interchange sign-in page. A timeout alone does not
identify the cause, so do not assume the five-minute setup-link expiry was
responsible unless the portal explicitly says the link expired.

If the retry fails, send Scope3 support this evidence:

* the approximate time of the failure, including time zone;
* your company domain and identity provider;
* browser name and version;
* the failed stage: domain check, redirect to the provider, provider sign-in,
  return to Interchange, or session creation;
* a screenshot of the error; and
* the diagnostic ID shown with the error, if one appears.

Never send browser cookies, OAuth authorization codes, access or refresh
tokens, passwords, or SAML assertions. Scope3 can correlate the diagnostic ID
and timestamp with privacy-safe server telemetry without those secrets.

## Next steps

<CardGroup cols={2}>
  <Card title="Authentication" href="/v2/authentication" icon="key">
    Learn about API key authentication
  </Card>

  <Card title="Management UI" href="/v2/ui-guide" icon="browser">
    Manage members, API keys, and more
  </Card>
</CardGroup>
