Skip to main content
With SAML single sign-on (SSO), your team signs in to Replit using your company’s identity provider, such as Microsoft Entra ID, Google Workspace, or Okta. You’ll need an Enterprise plan and admin access to both your Replit organization and your identity provider. This configures sign-in for your Replit organization, not authentication for an app you build.
Once SSO is active, people whose email addresses match your claimed domains must use SSO, including those with existing accounts. Coordinate with your identity administrator before activating it.
1

Open Advanced settings and enable SSO setup

Select your Enterprise Workspace, then select the Settings cogwheel in the bottom-left corner. Under Account, select Advanced.Expand Authentication and select Enable SSO on the SAML single sign-on card. This starts setup; SSO is not active yet.
Advanced settings showing the Authentication section and Enable SSO button on the SAML single sign-on card.

Advanced settings with Enable SSO under Authentication. Account details are examples.

2

Choose your identity provider

Under Configure your identity provider, select Microsoft Entra ID, Google Workspace, Okta, or Other provider.Replit displays the SAML values your provider needs. Copy the values from your own settings, not from the screenshot.
SAML setup marked In-progress, with identity provider choices, service provider values, and a Continue to Provider button.

Okta selected as the identity provider. The organization-specific identifier has been replaced with an example.

3

Continue to your provider

Select Continue to Provider and sign in to your identity provider’s admin console. The example below shows Okta; your provider’s sign-in screen may look different.
Okta sign-in screen with empty Username and Password fields.
Create a SAML application in your provider using the Audience URI / SP entity ID, SSO URL (ACS URL), Name ID format, and Application username values shown in Replit.
4

Complete configuration in Replit

Return to Replit and enter your provider’s IdP SSO URL, IdP entity ID, X.509 certificate, and the Email domains your organization uses.Follow the SAML configuration guide for the required values, domain validation rules, and activation steps. Submit the configuration and confirm the status becomes Active before directing teammates to use SSO.
SSO handles sign-in; it does not automatically invite people to your organization. Use invitations or SCIM provisioning to manage membership.

Optional: automate member management with SCIM

SCIM (System for Cross-domain Identity Management) automatically provisions and deprovisions members in Replit from your identity provider. SSO controls how people sign in; SCIM helps keep membership in sync as people join or leave your company. To start setup, open Settings → Advanced → Identity & Governance and select Enable SCIM under Automatic member provisioning (SCIM). Follow the provider-specific setup instructions in the SCIM guide.
Advanced settings showing Identity & Governance and the Enable SCIM button under Automatic member provisioning.

Enable SCIM from Advanced settings. Account details are examples.

Next step

Add collaborators

Invite collaborators and choose the access they need.