Skip to main content

Signing in to Deck

Deck supports multiple ways to sign in to the Console. All plans include social login. Enterprise plans unlock identity provider integrations for organizations that need centralized access control.

Social login

Every Deck account can sign in using email, Google, or GitHub. There is nothing to configure. Select your provider on the sign-in page and you’re in.

Enterprise SSO

Available to organizations on our Enterprise plan.
Enterprise SSO lets your organization sign in to Deck through your company’s identity provider instead of individual credentials.

Supported protocols and providers

Deck supports Enterprise SSO via SAML 2.0 and OpenID Connect (OIDC). Guided setup is available for the following SAML identity providers:
  • Microsoft Entra ID
  • Google Workspace
  • Okta Workforce
You can also connect any other IdP that supports the SAML or OIDC protocol.

Getting started

To get started, contact your Deck account team and ask them to enable SSO configuration for your organization. Once enabled, a Security tab appears in Organization Settings where an Admin can set up the connection. Before you begin, make sure you can publish DNS records for your company’s email domain and that you have admin access to your identity provider.

Setting up a connection

1

Verify your domain

In Organization Settings > Security, add your company’s email domain. You’ll receive a DNS TXT record to publish. Once the record is verified, members with a matching email address will sign in through your identity provider when the connection is active.
2

Choose your identity provider

Select Microsoft Entra ID, Google Workspace, or Okta Workforce for a guided setup, or choose custom SAML or OIDC for any other provider.
3

Configure the connection

Follow the guided steps for your provider. For custom SAML, you’ll be given an ACS URL and Entity ID to enter in your IdP, and your IdP must send the user’s email address as an attribute. For OIDC, you’ll need your provider’s client ID, client secret, and endpoints.
4

Test the connection

Run a test sign-in to confirm the connection works end to end. Testing does not affect existing members.
5

Activate the connection

Once activated, all members with a matching email domain must sign in through your identity provider. Changes to an active connection take effect immediately, so edit with care.

How it works

Once SSO is configured for your organization, members with a matching email domain are automatically added to your organization when they sign in through your identity provider. No invite is required. Members who joined through SSO cannot leave the organization on their own. Admins can remove them in Organization Settings, but if the member is not also removed from your IdP, they will rejoin on their next sign-in.