# Single sign-on (SSO)

> Signing in through your own identity provider (SAML) is not available yet. People sign in with their email, password and two-factor authentication.

Section: API, webhooks and security · Canonical: https://intubu.intuitivecapital-dai.com/docs/sso

**Single sign-on is not available yet.** IntuBu does not accept SAML sign-ins from an identity provider such as Okta or Microsoft Entra, and it cannot require SSO for your email domains. Everyone signs in with their email and password, and your organisation can require [Two-factor authentication](https://intubu.intuitivecapital-dai.com/docs/two-factor) authentication.

An SSO configuration (the identity provider's sign-on URL and signing certificate, and the domains it would apply to) can be saved through the API, but saving it does not change how anyone signs in.

Connecting a **mailbox** through its provider's own sign-in is a different thing, and does work — see [Connected app credentials](https://intubu.intuitivecapital-dai.com/docs/oauth-apps).
