Enterprise SSO
Let your team sign in to ThunderPhone through your company identity provider, with just-in-time provisioning and an organization-wide security policy you control.
Enterprise SSO lives on Settings → Organization (General tab), in the Enterprise SSO card. Flip the Single sign-on switch to reveal the configuration. Only organization admins and owners can see or change these settings.
Security policy
Three org-wide switches, saved together with Save Policy:
- Require SSO for sign-in — members must authenticate through your identity provider.
- Allow break-glass password sign-in for admins — an emergency password path for admins while SSO is enforced (only configurable when enforcement is on).
- Require passkeys for organization access — every member must register a passkey and pass a post-login passkey check. Members without one get a 3-day grace period to set it up; the policy panel shows how many members still need one.
SSO connections
ThunderPhone's SSO is backed by Stytch. Add connection creates one with:
| Field | What it does |
|---|---|
| Connection name | A label, e.g. "Acme Workspace SSO". |
| Default role for new users | Member, Admin, or Owner for accounts created via SSO. |
| Stytch organization slug / ID | Identifies your Stytch organization backing the connection. |
| Allowed email domains | Comma-separated domains permitted to sign in through it. |
| Group-to-role mappings | JSON array mapping IdP groups to roles, e.g. [{"group":"it-admins","role":"admin"}]. |
| Enable JIT provisioning | Auto-create ThunderPhone accounts on first SSO sign-in. |
| Connection active | Deactivate without deleting. |
Deleting a connection removes it permanently — users who signed in through it can no longer use it.