SSO is available on . You must be an organization Admin to view or
change SSO settings. You also need access to the domain’s DNS records and
permission to configure applications in your identity provider.
Configuration boundary
Horizon controls access to the setup workflow and shows its current state. WorkOS handles the provider-specific configuration.
You enter identity provider certificates, metadata, client credentials, and
secrets in WorkOS. Horizon requests portal links, reads non-secret domain and
connection status, and sends deletion requests to WorkOS. The provider
configuration does not pass through the Horizon API.
Verify domain
Domain verification proves that the organization controls the email domain that will use SSO. Horizon requires at least one verified domain before it lets you configure an identity provider connection.1
Open SSO settings
In the Horizon organization sidebar, find Govern and select
Single Sign-on. The page initially shows Domain verification
required.
2
Open WorkOS
Select Verify domain. Horizon generates a one-time link and opens the
WorkOS Admin Portal in a new tab.
3
Complete verification
Enter the domain your members use to sign in. Follow the WorkOS instructions
to add the required record to that domain’s DNS configuration. DNS changes
can take time to propagate, so wait for WorkOS to report that verification
succeeded before closing the portal.
4
Confirm the domain
Return to Horizon and reload the Single Sign-on page if its status has
not updated. The domain should show Verified, and the page should move
to SSO not configured.
Connect provider
An SSO connection tells WorkOS how to authenticate members with your identity provider. The WorkOS portal supplies the provider-specific values and prompts. Horizon does not collect them. Supported providers follow the WorkOS integration catalog. The catalog includes provider-specific SAML and OIDC integrations as well as generic protocol options for compatible identity providers.1
Open connection setup
Select Configure SSO. Horizon generates another one-time link and
opens the WorkOS Admin Portal.
2
Choose the protocol
Select your identity provider and configure the connection as SAML or OIDC.
For SAML, follow the portal prompts for metadata, sign-in URLs, identifiers,
and certificates. For OIDC, follow its prompts for issuer or discovery
details and client credentials.
3
Activate the connection
Complete the provider’s setup and validation in WorkOS. Keep the Horizon
administrator session open while you test the connection so you can return
to the settings page if the test fails.
4
Confirm SSO
Return to Horizon and reload the page if needed. The page shows SSO
enabled when it finds both a verified domain and an Active
connection.