> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tekma.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure enterprise SAML sign-in

> Set up owner-managed SAML SSO for one verified company domain when Enterprise access is enabled.

SAML appears under **Settings → Access** only when the deployment has an active Enterprise entitlement. Only a workspace owner can configure it. Before changing the connection, sign in within the last ten minutes and verify your Tekma authenticator.

## Configure the identity provider

1. Open **Settings → Access** and review the values Tekma displays for **ACS URL** and **Service provider entity ID**.
2. Create a SAML application in Okta, Microsoft Entra ID, Google Workspace, or another compatible provider using those values. Send a signed assertion with email and name attributes, a stable NameID, audience, recipient and timestamp conditions. Use SHA-256 or stronger.
3. In Tekma, enter the **Company email domain**, **Identity provider entity ID**, and **Identity provider sign-in URL**. Paste the provider's public signing certificate in PEM format; never paste a private key.
4. Choose **Save SAML configuration**. Saving or replacing configuration disables SSO until DNS is verified again.

## Verify and enable

Publish the `_tekma-saml` DNS proof shown by Tekma for the exact company domain. The proof is valid for seven days. Choose **Verify DNS and enable SSO**. Reverify the same record when it expires or when Tekma asks after a configuration change.

Test the SP-initiated company sign-in in a separate window before directing teammates to it. Existing verified members can use company sign-in when the deployment enables that path. Password sign-in and Tekma MFA remain available; Tekma continues to manage membership and roles.

## Limits and recovery

Tekma does not promise just-in-time account creation, IdP-initiated sign-in, enforced SSO, multiple domains, or single logout. If verification fails, confirm the exact domain, TXT proof, provider certificate and ACS/entity values, then retry after DNS propagation. Disabling SSO stops new SAML logins but does not terminate sessions that already exist.
