support@onesignal.com to get started. Having a product owner for SSO on setup calls helps streamline the process.What is SSO?
Single Sign-On lets team members log in to OneSignal using your organization’s identity provider (IdP) instead of a separate username and password. After authenticating once through your IdP, the user receives a token that grants access to OneSignal and your other SaaS applications without additional sign-in prompts.Supported identity providers
OneSignal supports SAML 2.0 and OpenID Connect (OIDC). Use whichever your IdP supports. The SSO experience is the same.View supported identity providers
View supported identity providers
support@onesignal.com to request it.Setup
- Eligibility: Enterprise plans and the Legal & Security package.
- Who sets it up: The person configuring SSO, who must also be a OneSignal org admin.
Steps
Contact support with your details
support@onesignal.com with the following:- Your OneSignal org name and org ID.
- The email domains to enable for SSO. Domains must match exactly (
onesignal.comwon’t coveronesignal.net). You can register multiple domains. - Email addresses of any pilot users to test with first. They must already be members of your organization.
Configure your identity provider

Configure your identity provider from the setup link

Select your identity provider from the list
Test with pilot users

OneSignal sign-in page with SSO option
Go live
Add users to your SSO organization
Once SSO is live, you add new team members by inviting them from the OneSignal dashboard. An org admin sends the invite, the user accepts it, and then they sign in through your identity provider. There’s no limit on the number of users in an SSO organization.Admin invites the user

Team Members page with Invite to Organization button

Enter the email address to invite
User accepts the invitation

Invitation email sent to the new team member
User signs in with SSO

SSO login page after accepting the invitation
Domain requirements
SSO maps email domains to your organization. For example,onesignal.com covers every @onesignal.com address. An organization can register multiple domains, so you can cover several email domains under the same SSO setup.
The user’s email domain must be registered under your SSO organization. If you invite someone whose domain is not registered, the invite fails with an error. To add a new domain, contact support@onesignal.com.

Error when inviting a user outside your SSO organization's domain
FAQ
How do I add or remove users?
Add and remove users from the Team Members page in the OneSignal dashboard. Provisioning and de-provisioning directly through your IdP is not currently supported.Can I limit who can sign in with SSO?
Yes. Access is controlled at two levels, and both must grant access:- Identity provider: Most IdPs (Okta, Google Workspace, Microsoft Entra ID, etc.) let you assign the OneSignal app to specific users, groups, or organizational units.
- OneSignal invite: Users must also be invited to your organization. Authenticating through your IdP alone is not enough.