SSO bypass
- Category
- SSO
- Published
Let specific users sign in with an email code when their enterprise SSO connection is unavailable.
An active enterprise single sign-on (SSO) connection requires users on its domains to sign in through an identity provider (IdP). If the IdP goes down or the connection breaks because a certificate expires or a setting changes, those users can't sign in, including the people who need to fix the connection.
SSO bypass lets users on an allowlist sign in with a one-time email code instead of using the IdP. Everyone else must continue to use SSO.
How it works
Add users to a connection's allowlist. When one of them enters their email address, <SignIn /> shows a Can't use SSO? link next to the SSO option. After confirming they want to continue without SSO, they get a code by email and sign in with an ordinary session. Users who aren't on the allowlist don't see the link.
You can only add users with a verified email address on a domain the connection serves. Clerk doesn't check whether the address still exists in your IdP. Clerk records each successful bypass as a sign_in.sso_bypass.succeeded event in Application Logs.
Who manages the allowlist
- You can manage the allowlist from the connection's page in the Clerk Dashboard or with the Backend API. Both options work whether or not your application uses Organizations.
- Organization members with the
org:sys_entconns_sso_bypass:managesystem permission can manage their Organization's allowlist from the Security tab of<OrganizationProfile />. The default Admin role includes this permission. They can add one member or all members with a given role.
Get started
SSO bypass is available on every instance with enterprise connections. To use it, enable Email verification code sign-in and add users to an allowlist. Read the SSO bypass guide to learn more, including how to support it in a custom sign-in flow.