Single Sign-On (SSO)

With Clym's Single Sign-On (SSO) functionality, you can streamline user authentication by enabling team members to access the Clym Control Center using their organization's existing email credentials. Rather than managing separate usernames and passwords, users can securely sign in with their company accounts, creating a seamless authentication experience while reducing password-related friction. Implementing SSO within your Clym account enhances security, improves operational efficiency, and simplifies user access management by centralizing authentication through your organization's identity provider.


Configuring Single Sign-On is an easy 3-step process:



1. Sign in to your Clym Control Center account


You should have received a magic link in your initial onboarding email. Please click Sign in from the email to get started. Alternatively, navigate to Clym's home page and click Sign in in the upper right-hand corner.


From the left side menu, select Configure and expand the Access section to find SSO.



Please note that SSO is only available to domains on the Perform plan. If you do not see SSO enabled on your account, please contact support@clym.io.


2. Enable Single Sign-On


In the top right corner, click Enable Single Sign-On (SSO).





3. Configure Single Sign-On


In the window that opens, configure the following fields below. Click Setup to continue.


  • SSO link slug: A unique identifier used to create your organization's SSO sign-in URL. Choose something recognizable, such as your company name. Please use an alpha-numeric string with no whitespace, only dashes. eg: my-company-name
  • Welcome title: Display message that your company sees when signing into Clym via single sign-on. eg: Welcome to our company SSO.
  • Enforce SSO user management: Enabling this will require all non-owner user accounts to sign in with SSO in order to access this company.
  • Callback URL: This field will automatically be populated by Clym. Use the Copy button to copy the URL when configuring Clym in your SSO provider.
  • Provider name: A friendly name for your SSO connection that is used for identification within Clym. Eg: Corporate SSO.
  • Provider type: The authentication protocol your identity provider uses (OpenID Connect, SAML 2.0, Magic link).
  • Provider: Select the identity provider your organization uses, such as Google, Gitlab (cloud), Github, or Microsoft.
  • Client ID: A unique identifier generated by your identity provider that tells Clym which application is requesting authentication.
  • Client secret: A secure credential generated by your identity provider that verifies Clym is authorized to communicate with your identity provider. Treat this like a password and keep it confidential.
  • Scopes: Defines what user information Clym is allowed to request from your identity provider during sign-in, such as a user's email address or profile information.
  • Issuer: The unique URL that identifies your identity provider and allows Clym to verify authentication requests are coming from the correct source.
  • Authorization endpoint: The URL where users are sent to sign in with your identity provider.
  • Token endpoint: The URL Clym uses to securely exchange authentication information for an access token after a user signs in.
  • User-info endpoint: An optional URL that allows Clym to retrieve additional user details, such as a user's name or email address, after authentication.
  • Revocation endpoint: An optional URL used to invalidate or revoke authentication tokens if a user's access needs to be terminated.
  • JWKS endpoint: The URL where Clym retrieves your identity provider's public security keys to verify that authentication tokens are valid and haven't been tampered with.
  • Allowed domains: Specifies which email domains are permitted to sign in using this SSO configuration (for example, yourcompany.com). This helps prevent unauthorized users from accessing your organization.
  • Session duration: Determines how long a user remains signed in before they are required to authenticate again.
  • Auto-provision users: Automatically creates a new Clym user account the first time someone successfully signs in through SSO, eliminating the need to manually invite or create users. Disabling user auto-provisioning will only allow manually created user accounts to sign in.
    • Default role: Determines which user role is automatically applied to a new user.



If you encounter any challenges, please reach out to support@clym.io.

Updated on: 09/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!