Requirements
Enterprise SSO and SCIM require an enabled enterprise organization, verified domains, and configuration by an authorized administrator. Astral validates issuer, redirect, audience, signing, and provisioning inputs before activation.
Configure OIDC sign-in
- Verify the organization domain in Astral.
- Register Astral's exact redirect URL with the identity provider.
- Enter the issuer, client ID, and approved claim mapping.
- Test with a non-break-glass administrator before enforcing SSO.
Provision with SCIM
Use a dedicated bearer token with the narrowest possible scope. SCIM creates, updates, suspends, and removes organization memberships; group mappings assign the configured workspace roles.
Note: Deprovisioning removes access but does not transfer data ownership automatically. Review workspace ownership before disabling the last owner.
Keep a break-glass path
Maintain a separately protected administrator account that does not depend on the same identity-provider session. Audit its use, protect it with strong MFA, and test the recovery procedure on a schedule.