SAML SSO

In this help doc

Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.

Jump to FAQs

Note: This feature is only available for users on the Business plan or Enterprise plan.

With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.

To use SSO with Notion:

  • Your workspace must be on a Business plan or Enterprise plan.

  • Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →

  • A workspace owner must configure SAML SSO for the Notion workspace.

  • At least one domain must be verified by a workspace owner. Learn more about domain verification →

Note: Only workspace members can use SAML SSO to log in. Guests invited to pages in a SAML-enabled Notion workspace can’t log in with SAML SSO. Instead, they’ll need to use another login method, like their username and password or login with Google or Apple.

Business plan

To set up SAML SSO for a Business workspace, a workspace owner can:

  1. Go to SettingsGeneral.

  2. In the Allowed email domainssection, remove all email domains.

  3. Select the Identity tab in Settings.

  4. Toggle on Enable SAML SSO and the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.

  5. The SAML SSO Configuration modal is divided into two parts:

    • The Assertion Consumer Service (ACS) URL needs to be entered in your Identity Provider (IdP) portal.

    • The Identity Provider Details is a field in which you need to provide either an IdP URL or IdP metadata XML.

  6. Choose how people sign in and whether new accounts are created for them, then select Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Note: A Business plan workspace uses one SAML configuration. If you need more than one identity provider, you must upgrade to the Enterprise plan.

Enterprise plan

Enterprise plan organisation owners can manage SAML SSO for every workspace in their organisation. An organisation can have more than one SAML configuration, so different groups of people can sign in with different identity providers. This is helpful when business units, regional IT teams, or companies you’ve acquired each have their own provider.

Note: An organisation can have up to 25 SAML configurations. There’s no limit on how many domains you verify.

To add a new SAML configuration:

  1. Open the workspace switcher and select Manage organisation. You may need to select Set up organisation first if you haven’t already. Learn more about organisation level controls here →

  2. In the General tab of your organisation settings, click SAML configurations. You’ll see every SAML configuration your organisation has.

  3. Select Create configuration and give it a name your team will recognise, like the business unit or provider it belongs to.

  4. Select Enable SAML SSO for login to set this as a login option for the selected email domains.

  5. Set the Login method for the people this configuration covers. Choose Any method to let users sign in with this SAML as an additional login option, or Only SAML SSO which requires users to sign in with this SAML only.

  6. Select Automatic account creation to automatically create accounts for new SAML SSO users who sign up using one of the selected email domains.

  7. Choose one or more verified email domains for the configuration. Adding a verified domain means any user that logs in with that domain will be able to use this SAML. A domain has to be verified before you can add it. See instructions for domain verification here →

  8. Copy the Assertion Consumer Service (ACS) URL for this configuration and add it in your identity provider. Each configuration has its own ACS URL, so give each provider its own app on their side.

  9. Copy the SAML SSO Entity ID for this configuration and add it to your identity provider.

  10. Choose whether to add your provider’s details with an IdP metadata URL or IdP metadata XML.

  11. Paste the URL from your IDP, then save.

Note: If your organisation already uses SAML SSO, that setup carries over as your first configuration. Your verified domains stay attached to it, and no one has to sign in again.

Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.

You can pick this while you are first setting up SAML, in the same save. You can also change it later.

If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.

On the Enterprise plan, you set this for each configuration. Setting the Login method to Only SAML SSO applies to the domains in that configuration and leaves your other configurations alone. A domain can be part of several configurations, but only one of them can be required at a time.

On the Business plan, this will look like this:

On the Enterprise plan, this will look like this:

SSO bypass

In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.

  • If a SAML configuration is managed at the organisation level, only organisation owners will be able to bypass SSO.

  • If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.

This works the same when your organisation has more than one configuration. An organisation owner can sign in with an email and password, then fix, turn off, or stop requiring the configuration that is causing the problem.

Note: This feature is only available to users on the Enterprise Plan. Domain verification is not required to enable this feature.

Workspace-level SAML authorisation allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.

To enable workspace-level SAML authorisation:

  1. Open the workspace switcher and select Manage organisation. You may need to Set up organisation first if you haven’t already. Learn more about organisation level controls here →

  2. In the General tab of your organisation settings, select SAML configurations.

  3. In the list of workspaces, pick which SAML configuration each workspace requires. You can leave a workspace without one.

Note: Before enabling, ensure all members are added to your Identity Provider (IdP) to prevent accidental lockouts from the workspace.

When enabled, members of the affected workspaces who haven’t already authorised with your organisation’s IdP will be met with an additional authorisation screen. They’ll need to go through SAML SSO to continue viewing your organisation’s workspaces.

If a workspace requires a specific configuration, members who haven’t signed in with that provider yet are asked to do it when they open the workspace. Notion brings them back to the workspace once they’re done. Someone who works in two workspaces that require different providers may be asked to sign in to each one.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.

To enable Just-in-Time provisioning if you're on the Business plan, go to SettingsIdentity and make sure that Automatic account creation is enabled.

To enable Just-in-Time provisioning if you’re on the Enterprise plan, go to your organisation settings → General and make sure that Automatic account creation is enabled.

On the Enterprise plan, you can turn Automatic account creation on or off for each configuration. The workspace that new people are added to is set for the whole organisation, so it’s the same no matter which provider they used. Give people access to other workspaces the way you normally would.

Note: We don’t recommend enabling Just-in Time provisioning if you are using SCIM. Having an “allowed email domain” in place allows users on that domain to join the workspace so there could be a mismatch between membership in their Identity Providers and Notion.

  • Business plan workspaces use one configuration. Enterprise plans allow for more than one SAML configuration.

  • An organisation can have up to 25 configurations. There is no limit on verified domains.

  • A verified domain can be part of several configurations, but only one of them can be required at a time.

  • A parent domain does not cover its subdomains. Verify each domain and subdomain you want to send to a provider, then add it to a configuration.

  • An email domain can belong to only one Notion organisation. Two organisations can't share it.

  • Only organisation owners, and admins who already manage SAML, can add or change configurations. Members can’t.


FAQs

Why can't I enable SAML SSO?

Why can’t I edit my SAML SSO settings?

It's possible you're trying to modify the verified domains or SSO configuration from a linked workspace that's already associated with another SSO configuration.

In linked workspaces, all domain management and SSO configuration settings are read-only. To modify the SSO configuration or remove this workspace from the SSO configuration, you must have access to the primary workspace. The name of the primary workspace can be found at the top of the Identity & Provisioningtab in your settings.

Why do I need to verify a domain to enable SSO?

We ask that the email domain ownership is validated to ensure that only the owner of the domain can customize how their users log into Notion.

I'm having trouble setting up SSO.

  • Try using a URL instead of an XML.

  • Test the setup process with a test account before enforcing it for users.

  • If neither of these options help, reach out to support at

Why should I remove email domains from the “Allowed Email Domains” setting before configuring SAML SSO for my workspace?

The Allowed Email Domain setting allows users with the selected domains to access your workspace without being provisioned via your IdP. To ensure that only users provisioned via your IdP can access your SAML-enabled workspace, disable this feature by removing all email addresses from the Allowed Email Domain list.

Can I still log in to Notion if my Identity Provider (IdP) is out of service?

Yes, even with SAML enforced, workspace owners have the option to log in with email. A workspace owner can change the SAML configuration to disable Enforce SAML so users can log in with email again.

How do I allow admins of other workspaces in my SAML configuration to create new workspaces?

Only the admins of your primary workspace will be able to create new workspaces using your verified domain(s). Please reach out to our support team ([email protected]) to switch your primary SAML workspace to another linked workspace in your SAML configuration.

Do I have to save my SAML settings twice?

No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.

Can each of our teams use its own identity provider?

Yes, if you’re on the Enterprise plan. An organisation owner can add a configuration for each provider and choose which verified email domains use it.

Can two providers be required for the same email domain?

No. A domain can be part of several configurations, but only one of them can be required at a time.

Still have questions? Message support

Give feedback

Was this resource helpful?


Powered by Fruition