Introduction
Single sign-on (SSO) lets everyone on your team log in to Gamma through your company's identity provider, like Okta, Microsoft Entra ID, or Google Workspace. Setup is fully self-serve and lives in your workspace settings, so most teams are up and running in minutes.
🔷 Note: SSO is available on Gamma's Business plan. You'll need workspace admin access, plus help from whoever manages your company's DNS records and identity provider (often the same IT admin).
Before you begin
Have these ready so setup goes smoothly.
A Gamma workspace on the Business plan.
Access to your domain's DNS settings, to verify you own your email domain.
Admin access to your identity provider. Gamma supports any SAML 2.0 or OIDC compliant provider, including Okta, Microsoft Entra ID, Google Workspace, OneLogin, Ping, Auth0, JumpCloud, and Rippling.
Setting up SSO
Step 1: Ask our team to enable SSO
From your workspace, go to Workspace Settings > Security & authentication.
If SSO hasn't been enabled for your workspace yet, you'll see a message that SSO isn't set up, along with a Contact support button. Click Contact support to send our team a quick email, and we'll enable SSO for your workspace and confirm as soon as it's ready.
Step 2: Add and verify your domain
Once SSO is enabled, head back to Workspace Settings > Security & authentication and select Add domain.
Enter your company's email domain, then follow the on-screen instructions to add a verification record to your DNS settings. The instructions are tailored to your DNS provider.
Your domain will show as Pending until the DNS record is detected, then switch to Verified.
🔷 Note: You can verify more than one domain, and people from any of your verified domains can share the workspace. Every domain you've added must be verified before SSO can be activated, and each domain can only belong to one Gamma workspace.
Step 3: Connect your identity provider
Once your domain is verified, select Continue to move to the identity provider step.
The guided setup walks you through connecting your provider, with detailed instructions and screenshots for each supported provider. Follow the steps shown in-app for your provider.
Step 4: Test and activate your connection
After your identity provider is connected, run the built-in connection test to confirm everything works, then activate SSO.
When setup is complete, the Security & authentication page shows that single sign-on is active. You'll also see options for session timeout and directory sync once SSO is live.
💎 Pro Tip: Add one workspace admin whose email is not on a verified domain (a personal address works). SSO is only enforced for verified-domain emails, so this account is your backup way in if your identity provider ever has an outage.
What happens after activation
After SSO is activated, there's a grace period of 7 days. After that, everyone whose email is on a verified domain signs in by choosing Continue with SSO on the login page. Password and Google login will no longer work for those accounts.
A few things you can manage once SSO is active:
Session timeout. Choose how long sign-in sessions last: 1 hour, 8 hours, 24 hours, 7 days, or 30 days. The default is 7 days.
More domains. You can add and verify additional domains at any time.
Directory sync (SCIM). Manage workspace membership from your identity provider's directory.
FAQs & Common Issues
I'm struggling to log in with single-sign on - what are some troubleshooting tips?
Which identity providers does Gamma support?
Any SAML 2.0 or OIDC compliant provider.
That includes Okta, Microsoft Entra ID, Google Workspace, OneLogin, Ping, Auth0, JumpCloud, and Rippling, plus generic SAML connections.
How do new team members get Gamma accounts?
Assign them to Gamma in your identity provider.
Their account is created automatically the first time they sign in, and they join your workspace as a Member.
Gamma identifies people by a stable identifier from your provider, so name or email changes in your directory never break accounts.
My payment is still processing. Can I set up SSO?
Yes. As long as your workspace is on the Business plan, you can complete SSO setup while a payment is processing.
Does everyone have to use SSO?
Members whose email is on a verified domain must use SSO once the grace period ends.
Members on other domains (like a personal email) can keep logging in with their existing method.
If you'd like to require SSO for everyone on your domain, including people who haven't joined your workspace yet, reach out to us about domain capture.
What happens to personal Gamma accounts?
Nothing. Personal workspaces live alongside your company workspace, and their content isn't visible to workspace admins.
SSO login isn't working in Safari.
Safari occasionally has issues with SSO logins. We recommend using Chrome if you hit an error.
Can we turn SSO off later?
Reach out to our support team and we'll help you transition your team back to another sign-in method.
We use more than one email domain. Does that work?
Yes. Verify each domain and they all attach to the same workspace.
Just remember that activation completes only after every added domain is verified, and a domain can belong to only one Gamma workspace.
