TABLE OF CONTENTS
Overview
Single sign-on (SSO) does just what its name implies: it gives users access to multiple sites and online tools with a single login. If your users have already authenticated into your company network, SSO allows them to access Stack Internal directly without logging in again.
SSO authentication starts with an identity provider (IdP), which prompts your users for their credentials. The IdP then authenticates the user and sends them to your Stack Internal site, bypassing the need for the user to log in again.
The Stack Internal platform and the Stack Internal community use separate user and SSO configurations. If your organization uses both products, configure SSO for each product independently.
Stack Internal works with your existing IdP, whether that's Okta, Microsoft Entra ID, or any one of many other supported providers. Stack Internal makes the SSO setup process easier by using WorkOS as an intermediary between itself and your IdP.
WorkOS
WorkOS is the enterprise identity platform Stack Internal uses to connect to your IdP—it does not replace your IdP. Your organization continues to use your IdP to manage users, credentials, multifactor authentication, conditional-access policies, and other sign-in controls.
Within Stack Internal, WorkOS establishes the SAML or OIDC connection, routes users to the correct organization connection, returns verified authentication results, and alerts your site when identity configuration or membership information changes. All of that adds up to easier setup and management of your SSO integration.
How the pieces fit together
- Your identity provider authenticates users and enforces your corporate sign-in policies. You retain control of credentials, multi-factor authentication (MFA), and access policies.
- WorkOS connects the identity provider to Stack Internal using SAML or OIDC. WorkOS also hosts the initial setup flow, where a site administrator configures the connection through a guided portal.
- Stack Internal maps the authenticated user from the IdP to a Stack Internal workspace user, owns the product session, evaluates roles and permissions, and issues internal tokens.
Next steps
Follow the steps in the Configure SSO article to connect Stack Internal to your identity provider.
Get help
If you have questions or issues, reach out to our support team for help.