> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aixy-gateway.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On

> Connect Google Workspace and configure organization sign-in.

Enterprise organizations can connect Google Workspace for dashboard sign-in. Aixy keeps the
organization's roles, projects, API keys, and permissions; the identity provider authenticates the
person signing in.

## Connect Google Workspace

1. As an Owner or Org admin, open **Single Sign-On** from the account settings menu and choose
   **Connect identity provider → Google Workspace**.
2. Create a Google Web OAuth application and register the exact callback URL shown in the editor.
3. Enter the client ID, client secret, connection name, and Google Workspace domain.
4. Choose a project-only default role, including a custom role, and project assignments for newly provisioned members.
5. Save, completing the recent sign-in confirmation when prompted.

Use the callback displayed by Aixy. Keep the secret in the setup form and avoid reloading while
confirming your identity; the form draft is held only in memory.

## Verify member access

Enter your email at sign-in and choose **Continue with organization SSO**. Test with a project-role account and
confirm its role and projects in **Users**. Existing users with organization-administration permissions explicitly link from a
recent passkey-authenticated session; matching their email alone does not link a protected account.

SSO can provision a Project user or Project admin with the configured default projects. Protected
organization roles remain an explicit Owner decision. An authenticated organization picker can
start SSO for the selected organization. If email discovery is ambiguous, sign in with your personal
password or passkey and choose the organization. SSO proof applies to its originating organization
and to organizations you [create while signed in](/administration/organization#create-another-organization)
or explicitly join through an invitation using that provider. Returning to those organizations requires the same active provider and
membership in the original organization. Their own required SSO policy still applies; the proof
does not unlock unrelated memberships or allow account password/passkey changes.

## Require SSO

Before enabling **Require Single Sign-On**, the Owner must register a passkey and confirm the
recovery Owner. Verify the Google connection and the Owner's recovery sign-in first.

Enabling required SSO revokes local sessions for that organization and requires its identity
provider before entering it. Personal password recovery does not bypass this policy. The designated
Owner retains a passkey recovery path. Keep this account available and protected;
disable required SSO before disconnecting its identity provider.

## Offboard a member

Use [user suspension](/administration/organization#suspend-or-remove-access) in Aixy to revoke
sessions, project API keys, and MCP tokens. Treat Aixy offboarding as an explicit administration
step. Removing an identity connection blocks new logins and revokes its SSO sessions while cleanup
completes.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.