ThunderPhone 2.0 is live.Self-serve, from 2¢/min.Read the announcement

Team & account

Enterprise SSO

Let your team sign in to ThunderPhone through your company identity provider, with just-in-time provisioning and an organization-wide security policy you control.

Enterprise SSO lives on Settings → Organization (General tab), in the Enterprise SSO card. Flip the Single sign-on switch to reveal the configuration. Only organization admins and owners can see or change these settings.

Security policy

Three org-wide switches, saved together with Save Policy:

  • Require SSO for sign-in — members must authenticate through your identity provider.
  • Allow break-glass password sign-in for admins — an emergency password path for admins while SSO is enforced (only configurable when enforcement is on).
  • Require passkeys for organization access — every member must register a passkey and pass a post-login passkey check. Members without one get a 3-day grace period to set it up; the policy panel shows how many members still need one.

SSO connections

ThunderPhone's SSO is backed by Stytch. Add connection creates one with:

FieldWhat it does
Connection nameA label, e.g. "Acme Workspace SSO".
Default role for new usersMember, Admin, or Owner for accounts created via SSO.
Stytch organization slug / IDIdentifies your Stytch organization backing the connection.
Allowed email domainsComma-separated domains permitted to sign in through it.
Group-to-role mappingsJSON array mapping IdP groups to roles, e.g. [{"group":"it-admins","role":"admin"}].
Enable JIT provisioningAuto-create ThunderPhone accounts on first SSO sign-in.
Connection activeDeactivate without deleting.

Deleting a connection removes it permanently — users who signed in through it can no longer use it.

Next steps