Single Sign-On (SSO) lets your team sign in to Compound through your organization’s identity provider (IdP) instead of managing separate passwords. Once configured, team members with your verified email domain are prompted to authenticate via SSO when they sign in.
Prerequisites
Before you begin, make sure you have the following:
- A Compound team. SSO is a team feature. If you don’t have a team yet, go to
/teamin Compound (for example,getcompound.ai/team) and create one under Create a Team. The person who creates the team becomes the Owner. - The Team Owner role. Only Team Owners can configure SSO. Admins and Members cannot access SSO settings.
- A custom email domain. Public email domains (e.g., gmail.com, outlook.com) cannot be used for SSO.
Verify your domain
Domain verification is required before you can enable SSO. It proves that your organization controls the email domain and prevents other teams from claiming it.
Set your team's email domain
In Settings > Organization > Security, enter your organization’s email domain (e.g., acme.com) in the Email Domain field. It saves when you click out of the field.
Start domain verification
In the Details section, click the Verify badge next to your domain (only the Owner sees it). Compound generates a unique verification token and displays DNS record instructions.
Add the DNS TXT record
Log in to your domain registrar or DNS provider and create a new TXT record with the following values:
- Type:
TXT - Host:
@(root domain) - Value:
compound-domain-verification=<your-token>
Copy the exact value shown in Compound. It includes your unique token.
DNS changes can take anywhere from a few minutes to 72 hours to propagate, depending on your DNS provider and TTL settings. Most providers propagate within 5-15 minutes.
Complete verification
Return to Settings > Organization > Security. If the verification panel is closed, click Verify again (the token stays the same), then click Check Verification. Compound performs a DNS lookup to confirm your TXT record is in place. Once verified, a green Verified badge appears next to your domain.
Each domain can only be verified by one team. If another team has already verified the same domain, you will need to contact support.
Supported protocols
Compound supports two standard SSO protocols.
OpenID Connect (OIDC) — Recommended
OIDC is the modern standard for SSO, built on OAuth 2.0 with JSON-based tokens. It is simpler to configure, has better security properties (shorter-lived tokens, no XML signature vulnerabilities), and is the default recommendation from all major identity providers including Okta, Microsoft Entra ID, and Google Workspace.
Choose OIDC unless your organization requires SAML.
Configuration fields:
- Client ID
- Client Secret
- Issuer URL
SAML 2.0
SAML is a widely deployed SSO protocol that uses XML-based assertions. It remains fully supported for organizations with existing SAML infrastructure or compliance requirements that mandate it.
Configuration options:
- Upload your IdP’s metadata XML file (recommended, since it extracts the Entity ID, SSO URL, and certificate for you)
- Manually enter the IdP Entity ID, SSO URL, and X.509 signing certificate
Set up SSO with your identity provider
Once your domain is verified, follow the guide for your identity provider and protocol:
- Set Up Okta OIDC SSO: step-by-step guide for configuring OpenID Connect with Okta (recommended)
- Set Up Okta SAML SSO: step-by-step guide for configuring SAML 2.0 with Okta
For other identity providers (Azure AD, OneLogin, Google Workspace, etc.), the general flow is the same:
- Create a SAML or OIDC application in your IdP using temporary placeholder values for the callback/redirect URL.
- Enter the IdP credentials or metadata into Compound at Settings > Organization > Security > Security & access > Single Sign-On (SSO).
- After saving, Compound displays the SP metadata your IdP needs: ACS URL and SP Entity ID for SAML, or Redirect URI for OIDC. Copy these values back into your IdP’s application settings.
Refer to your IdP’s documentation for the specifics of creating a custom SAML or OIDC application.
What happens after SSO is configured
Once SSO is active for your team:
- Automatic SSO detection. When a user enters an email address with your verified domain on the Compound sign-in page, Compound detects that SSO is required and prompts them to sign in through your identity provider.
- Authentication with your IdP. Compound redirects the user to your IdP (e.g., Okta), where they sign in with their corporate credentials and any MFA policies you have configured.
- Signed in. After authenticating with your IdP, the user is signed in to Compound.
While SSO is active, the Email Domain field is hidden and Login restriction shows Enterprise SSO and can’t be changed. To change them, first remove the SSO configuration from Settings > Organization > Security > Security & access > Single Sign-On (SSO).
On an enterprise contract without SCIM, anyone who signs in through your IdP with an address on your verified domain joins your team as a Member automatically. On self-serve team plans, Compound doesn’t add them automatically: invite them from Settings > Organization > Members, or configure SCIM to provision users from your identity provider.
Automate user provisioning with SCIM
After SSO is configured, you can enable SCIM (System for Cross-domain Identity Management) to add and remove team members from your identity provider. When you assign a user to the Compound app in your IdP, they are provisioned to your team. When you unassign them, they are removed.
SCIM requires an active SSO configuration (SAML or OIDC) and can be enabled from Settings > Organization > Security > SCIM Provisioning. See SCIM Provisioning for setup instructions.