



Enterprise-ready, before your customer asks
Enterprise SSO and Directory Sync, out of the box.

Single Sign-On (SSO)
Enterprise customers arrive with their identity stack already chosen. Clerk federates into it — through the same <SignIn /> you already shipped, with no new SSO code.
Okta Workforce
Connect an Okta tenant over SAML or OIDC.
Microsoft Entra ID
Federate with Entra ID, formerly Azure AD.
Google Workspace
Sign in with the Workspace domain their IT team already manages.
Custom SAML provider
Any SAML 2.0 provider, configured from its metadata.
Custom OIDC provider
Any OIDC-compliant provider, via its discovery URL.
Directory Sync
Add Directory Sync and users are provisioned and deprovisioned straight from their IdP. When IT revokes access, it's revoked in your app — no stale accounts, no manual offboarding.
Read more
Use our tenant model, or bring your own
Enterprise connections work with whatever tenancy you've built.
Use Multi-tenancy
Connections attach to organizations, with members, roles, and invitations handled — and enterprise admins get self-serve setup, configuring SSO themselves from their organization profile.
Bring your own
Attach connections to the tenant model you already built. Clerk tells you who signed in and through which connection — your data model decides the rest.
Organization
Manage your organization
General
Members
Billing
Security
API keys
Security
SSO
ActiveRequire members with a matching email domain to sign in through your identity provider.
Okta Workforce
brightside.com
Verified domains
brightside.com
Self-serve SSO available with Multi-tenancy
Your first connection is free
Every app includes one enterprise connection — EASIE, SAML, or OIDC — at no cost. Close your first enterprise deal before you pay for SSO at all. After that, connections are priced per month, with volume discounts published up front.
See full pricing