# SSO bypass

An active enterprise single sign-on (SSO) connection requires users on its domains to sign in through an identity provider (IdP). If the IdP goes down or the connection breaks because a certificate expires or a setting changes, those users can't sign in, including the people who need to fix the connection.

SSO bypass lets users on an allowlist sign in with a one-time email code instead of using the IdP. Everyone else must continue to use SSO.

## How it works

Add users to a connection's allowlist. When one of them enters their email address, [`<SignIn />`](https://clerk.com/docs/reference/components/authentication/sign-in.md) shows a **Can't use SSO?** link next to the SSO option. After confirming they want to continue without SSO, they get a code by email and sign in with an ordinary session. Users who aren't on the allowlist don't see the link.

You can only add users with a verified email address on a domain the connection serves. Clerk doesn't check whether the address still exists in your IdP. Clerk records each successful bypass as a `sign_in.sso_bypass.succeeded` event in [Application Logs](https://clerk.com/docs/guides/dashboard/logs/application-logs.md).

## Who manages the allowlist

- **You** can manage the allowlist from the connection's page in the [Clerk Dashboard](https://dashboard.clerk.com/~/user-authentication/sso-connections/enterprise) or with the [Backend API](https://clerk.com/docs/reference/backend-api/tag/sso-bypass/POST/sso_bypass_allowlist_users). Both options work whether or not your application uses Organizations.
- **Organization members** with the `org:sys_entconns_sso_bypass:manage` [system permission](https://clerk.com/docs/guides/organizations/control-access/roles-and-permissions.md#system-permissions) can manage their Organization's allowlist from the **Security** tab of [`<OrganizationProfile />`](https://clerk.com/docs/reference/components/organization/organization-profile.md). The default [**Admin**](https://clerk.com/docs/guides/organizations/control-access/roles-and-permissions.md#default-roles) role includes this permission. They can add one member or all members with a given role.

## Get started

SSO bypass is available on every instance with enterprise connections. To use it, enable [**Email verification code**](https://clerk.com/docs/guides/configure/auth-strategies/sign-up-sign-in-options.md#email) sign-in and add users to an allowlist. Read the [SSO bypass guide](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/sso-bypass.md) to learn more, including how to support it in a custom sign-in flow.
