Set Up SSO for Compound

Last updated September 28, 2026

Single Sign-On (SSO) lets your team sign in to Compound through your organization’s identity provider (IdP) instead of managing separate passwords. Once configured, team members with your verified email domain are prompted to authenticate via SSO when they sign in.

Prerequisites

Before you begin, make sure you have the following:

  • A Compound team. SSO is a team feature. If you don’t have a team yet, go to /team in Compound (for example, getcompound.ai/team) and create one under Create a Team. The person who creates the team becomes the Owner.
  • The Team Owner role. Only Team Owners can configure SSO. Admins and Members cannot access SSO settings.
  • A custom email domain. Public email domains (e.g., gmail.com, outlook.com) cannot be used for SSO.

Verify your domain

Domain verification is required before you can enable SSO. It proves that your organization controls the email domain and prevents other teams from claiming it.

Set your team's email domain

In Settings > Organization > Security, enter your organization’s email domain (e.g., acme.com) in the Email Domain field. It saves when you click out of the field.

Start domain verification

In the Details section, click the Verify badge next to your domain (only the Owner sees it). Compound generates a unique verification token and displays DNS record instructions.

Add the DNS TXT record

Log in to your domain registrar or DNS provider and create a new TXT record with the following values:

  • Type: TXT
  • Host: @ (root domain)
  • Value: compound-domain-verification=<your-token>

Copy the exact value shown in Compound. It includes your unique token.

Note

DNS changes can take anywhere from a few minutes to 72 hours to propagate, depending on your DNS provider and TTL settings. Most providers propagate within 5-15 minutes.

Complete verification

Return to Settings > Organization > Security. If the verification panel is closed, click Verify again (the token stays the same), then click Check Verification. Compound performs a DNS lookup to confirm your TXT record is in place. Once verified, a green Verified badge appears next to your domain.

Important

Each domain can only be verified by one team. If another team has already verified the same domain, you will need to contact support.

Supported protocols

Compound supports two standard SSO protocols.

OpenID Connect (OIDC) — Recommended

OIDC is the modern standard for SSO, built on OAuth 2.0 with JSON-based tokens. It is simpler to configure, has better security properties (shorter-lived tokens, no XML signature vulnerabilities), and is the default recommendation from all major identity providers including Okta, Microsoft Entra ID, and Google Workspace.

Choose OIDC unless your organization requires SAML.

Configuration fields:

  • Client ID
  • Client Secret
  • Issuer URL

SAML 2.0

SAML is a widely deployed SSO protocol that uses XML-based assertions. It remains fully supported for organizations with existing SAML infrastructure or compliance requirements that mandate it.

Configuration options:

  • Upload your IdP’s metadata XML file (recommended, since it extracts the Entity ID, SSO URL, and certificate for you)
  • Manually enter the IdP Entity ID, SSO URL, and X.509 signing certificate

Set up SSO with your identity provider

Once your domain is verified, follow the guide for your identity provider and protocol:

For other identity providers (Azure AD, OneLogin, Google Workspace, etc.), the general flow is the same:

  1. Create a SAML or OIDC application in your IdP using temporary placeholder values for the callback/redirect URL.
  2. Enter the IdP credentials or metadata into Compound at Settings > Organization > Security > Security & access > Single Sign-On (SSO).
  3. After saving, Compound displays the SP metadata your IdP needs: ACS URL and SP Entity ID for SAML, or Redirect URI for OIDC. Copy these values back into your IdP’s application settings.

Refer to your IdP’s documentation for the specifics of creating a custom SAML or OIDC application.

What happens after SSO is configured

Once SSO is active for your team:

  1. Automatic SSO detection. When a user enters an email address with your verified domain on the Compound sign-in page, Compound detects that SSO is required and prompts them to sign in through your identity provider.
  2. Authentication with your IdP. Compound redirects the user to your IdP (e.g., Okta), where they sign in with their corporate credentials and any MFA policies you have configured.
  3. Signed in. After authenticating with your IdP, the user is signed in to Compound.
Note

While SSO is active, the Email Domain field is hidden and Login restriction shows Enterprise SSO and can’t be changed. To change them, first remove the SSO configuration from Settings > Organization > Security > Security & access > Single Sign-On (SSO).

On an enterprise contract without SCIM, anyone who signs in through your IdP with an address on your verified domain joins your team as a Member automatically. On self-serve team plans, Compound doesn’t add them automatically: invite them from Settings > Organization > Members, or configure SCIM to provision users from your identity provider.

Automate user provisioning with SCIM

After SSO is configured, you can enable SCIM (System for Cross-domain Identity Management) to add and remove team members from your identity provider. When you assign a user to the Compound app in your IdP, they are provisioned to your team. When you unassign them, they are removed.

SCIM requires an active SSO configuration (SAML or OIDC) and can be enabled from Settings > Organization > Security > SCIM Provisioning. See SCIM Provisioning for setup instructions.