Skip to main content

Enterprise-ready, before your customer asks

Enterprise SSO and Directory Sync, out of the box.

A customer's IT admin choosing their identity provider — Okta Workforce, Microsoft Entra ID, Google Workspace, or a custom SAML provider — inside the Security tab, with steps for domains, connection, test, and activate.

Single Sign-On (SSO)

Enterprise customers arrive with their identity stack already chosen. Clerk federates into it — through the same <SignIn /> you already shipped, with no new SSO code.

  • Okta Workforce

    Connect an Okta tenant over SAML or OIDC.

  • Microsoft Entra ID

    Federate with Entra ID, formerly Azure AD.

  • Google Workspace

    Sign in with the Workspace domain their IT team already manages.

  • Custom SAML provider

    Any SAML 2.0 provider, configured from its metadata.

  • Custom OIDC provider

    Any OIDC-compliant provider, via its discovery URL.

SCIM

Directory Sync

Add Directory Sync and users are provisioned and deprovisioned straight from their IdP. When IT revokes access, it's revoked in your app — no stale accounts, no manual offboarding.

Read more
A directory sync diagram: Okta, Microsoft Entra ID, or a custom provider pushes add, update, and deactivate events through Clerk to a live list of application users, where a deactivated user is greyed out.

Use our tenant model, or bring your own

Enterprise connections work with whatever tenancy you've built.

Use Multi-tenancy

Connections attach to organizations, with members, roles, and invitations handled — and enterprise admins get self-serve setup, configuring SSO themselves from their organization profile.

Bring your own

Attach connections to the tenant model you already built. Clerk tells you who signed in and through which connection — your data model decides the rest.

Organization

Manage your organization

General

Members

Billing

Security

API keys

Secured by

Security


SSO

Active

Require members with a matching email domain to sign in through your identity provider.

Start configuration

Okta Workforce

brightside.com

Active

Verified domains

brightside.com

Self-serve SSO available with Multi-tenancy

Your first connection is free

Every app includes one enterprise connection — EASIE, SAML, or OIDC — at no cost. Close your first enterprise deal before you pay for SSO at all. After that, connections are priced per month, with volume discounts published up front.

See full pricing
Enterprise connections
1 connectionincluded per app
2 - 15$75/mo each
16 - 100$60/mo each
101 - 500$30/mo each
500+$15/mo each