SSO
Connect your identity provider with OIDC or SAML via Better Auth SSO. Configure in Settings when your workspace has the SSO entitlement.
Setup#
Enterprise admins configure IdP clients under Settings → SSO. Client secrets can use a dedicated SSO_ENCRYPTION_KEY or a key derived from BETTER_AUTH_SECRET. Extra discovery origins: SSO_TRUSTED_ORIGINS.
Login also exposes “Continue with SSO” for enterprise email domains when configured.
Plans#
Requires Enterprise (sso).
Limitations
- Settings UI is hidden without entitlement.
- IdP dry-run against customer IdPs should be part of any POC.