Skip to main content
Single sign-on (SSO) connects a Horizon organization to an identity provider. After setup, members with email addresses on the verified domain sign in through the organization’s identity provider.
SSO is available on . You must be an organization Admin to view or change SSO settings. You also need access to the domain’s DNS records and permission to configure applications in your identity provider.
Horizon delegates domain verification and identity provider configuration to the WorkOS Admin Portal. Each setup action in Horizon opens a one-time WorkOS portal link. Open the link immediately and complete the task in that browser tab.

Configuration boundary

Horizon controls access to the setup workflow and shows its current state. WorkOS handles the provider-specific configuration. You enter identity provider certificates, metadata, client credentials, and secrets in WorkOS. Horizon requests portal links, reads non-secret domain and connection status, and sends deletion requests to WorkOS. The provider configuration does not pass through the Horizon API.

Verify domain

Domain verification proves that the organization controls the email domain that will use SSO. Horizon requires at least one verified domain before it lets you configure an identity provider connection.
1

Open SSO settings

In the Horizon organization sidebar, find Govern and select Single Sign-on. The page initially shows Domain verification required.
2

Open WorkOS

Select Verify domain. Horizon generates a one-time link and opens the WorkOS Admin Portal in a new tab.
3

Complete verification

Enter the domain your members use to sign in. Follow the WorkOS instructions to add the required record to that domain’s DNS configuration. DNS changes can take time to propagate, so wait for WorkOS to report that verification succeeded before closing the portal.
4

Confirm the domain

Return to Horizon and reload the Single Sign-on page if its status has not updated. The domain should show Verified, and the page should move to SSO not configured.

Connect provider

An SSO connection tells WorkOS how to authenticate members with your identity provider. The WorkOS portal supplies the provider-specific values and prompts. Horizon does not collect them. Supported providers follow the WorkOS integration catalog. The catalog includes provider-specific SAML and OIDC integrations as well as generic protocol options for compatible identity providers.
1

Open connection setup

Select Configure SSO. Horizon generates another one-time link and opens the WorkOS Admin Portal.
2

Choose the protocol

Select your identity provider and configure the connection as SAML or OIDC. For SAML, follow the portal prompts for metadata, sign-in URLs, identifiers, and certificates. For OIDC, follow its prompts for issuer or discovery details and client credentials.
3

Activate the connection

Complete the provider’s setup and validation in WorkOS. Keep the Horizon administrator session open while you test the connection so you can return to the settings page if the test fails.
4

Confirm SSO

Return to Horizon and reload the page if needed. The page shows SSO enabled when it finds both a verified domain and an Active connection.

Verify sign-in

Test with a member whose email address uses the verified domain. Open a private browser window, go to the Horizon sign-in page, and enter that member’s work email address. WorkOS identifies the domain and sends the member to the organization’s identity provider. After the identity provider authenticates the member, the browser returns to Horizon. SSO changes authentication. Use Directory Sync for identity-provider-managed provisioning and deprovisioning. SSO does not change organization or server access. The member keeps the permissions assigned through their organization and server roles.

SSO states

After SSO is available on the organization’s plan, Horizon reads the current domain and connection status from WorkOS and reduces it to one setup state.

Manage SSO

When SSO is enabled, select Manage SSO to generate a new one-time WorkOS portal link. Use it to review or update the provider configuration. Organization admins can also delete domains and connections from Horizon. Deleting the last active connection moves the organization back to SSO not configured. Deleting its last verified domain moves it back to Domain verification required. Deletion cannot be undone, so keep the existing configuration until the replacement domain or connection is ready.