SAML / SSO
Connect your identity provider and manage access centrally.
Enterprise workspaces can require sign-in through your identity provider. Arshas supports SAML 2.0 and OIDC, and works out of the box with Okta, Microsoft Entra ID, Google Workspace, and any standards-compliant IdP.
Setting it up
From the admin console, open Security → Single sign-on and exchange metadata with your IdP: upload their metadata XML (or paste the OIDC issuer URL), and register the Arshas callback URL on their side. A test-login button validates the handshake before you enforce it.
Once verified, flip enforcement on. Existing sessions are migrated on next sign-in, and members who leave your IdP lose Arshas access automatically.
Provisioning
SCIM provisioning is available alongside SSO: create, deactivate, and group-sync members from your directory. Seats free up automatically when users are deprovisioned, and audit logs record every authentication event for your security team.