Skip to main content

SSO bypass

Category
SSO
Published

Let specific users sign in with an email code when their enterprise SSO connection is unavailable.

An active enterprise single sign-on (SSO) connection requires users on its domains to sign in through an identity provider (IdP). If the IdP goes down or the connection breaks because a certificate expires or a setting changes, those users can't sign in, including the people who need to fix the connection.

SSO bypass lets users on an allowlist sign in with a one-time email code instead of using the IdP. Everyone else must continue to use SSO.

How it works

Add users to a connection's allowlist. When one of them enters their email address, <SignIn /> shows a Can't use SSO? link next to the SSO option. After confirming they want to continue without SSO, they get a code by email and sign in with an ordinary session. Users who aren't on the allowlist don't see the link.

You can only add users with a verified email address on a domain the connection serves. Clerk doesn't check whether the address still exists in your IdP. Clerk records each successful bypass as a sign_in.sso_bypass.succeeded event in Application Logs.

Who manages the allowlist

  • You can manage the allowlist from the connection's page in the Clerk Dashboard or with the Backend API. Both options work whether or not your application uses Organizations.
  • Organization members with the org:sys_entconns_sso_bypass:manage system permission can manage their Organization's allowlist from the Security tab of <OrganizationProfile />. The default Admin role includes this permission. They can add one member or all members with a given role.

Get started

SSO bypass is available on every instance with enterprise connections. To use it, enable Email verification code sign-in and add users to an allowlist. Read the SSO bypass guide to learn more, including how to support it in a custom sign-in flow.

Contributors
Maurício Antunes
Stephen Sibley
Steve Hayes

Share this article