> For clean Markdown of any page, append `.md` to the page URL.
> Documentation index: https://you.com/docs/llms.txt (section indexes: append `/llms.txt` to any section URL).
> Search these docs: Docs MCP at https://you.com/docs/_mcp/server (`searchDocs`, no API key).
> Call live You.com APIs: Product MCP at https://api.you.com/mcp (keyless `?profile=free` exposes `you-search` and `you-discover`. Research and finance use `/mcp/research`, `/mcp/finance`, or `?tools=` on `/mcp`). To pick an API or integration path, call `you-discover` on that server instead of guessing.
> OpenAPI: https://you.com/docs/openapi.json—auth header `X-API-Key`, env `YDC_API_KEY`.

# SSO and SCIM

## Overview

Enterprise organizations on the You.com Platform can authenticate members through their own identity provider (IdP) and provision those members with System for Cross-domain Identity Management (SCIM). You.com issues the SAML 2.0 and SCIM endpoints. A Customer Success Architect (CSA) enables the connection on a scheduled configuration call. There is no self-serve toggle in Platform settings.

SSO can require IdP login for users whose email is on the domains you list at enablement. Depending on how the CSA configures the connection, the first successful login on a covered domain may create the You.com user (just-in-time provisioning), or users may appear only after a SCIM create.

> **Info**
>
> To start enablement, email [api@you.com](mailto:api@you.com) or your You.com account team. Bring an IdP administrator and a You.com organization Admin or Owner to the configuration call.

## What SSO and SCIM Cover

**SSO (SAML 2.0).** Members on a configured email domain sign in through your IdP. Once enforcement is on, those users cannot use Google, Apple, or email one-time-password buttons on the Platform login page, even when the IdP itself is Google Workspace.

**SCIM.** Your IdP creates, updates, and deprovisions You.com users. Deactivation in the IdP is what removes access. Manual cleanup in Platform is a fallback, not the primary offboarding path.

SCIM-provisioned users land in the organization [member list](/docs/administration/team-management) (**Settings → Members**), with roles (Owner, Admin, Developer, Billing) set during enablement with your CSA. Do not assume a default mapping from IdP group names to those roles.

> **Note**
>
> Older IdP app catalogs sometimes label the You.com SAML application **Descope - You.com**. You.com historically used Descope as an intermediate provisioning layer. Configure against the Entity ID, ACS URL, and SCIM token your CSA issues for You.com. Treat any Descope label as a catalog leftover, not the product name.

## Prerequisites

Before the configuration call, have:

* The list of email domains SSO should cover
* A test IdP group that includes at least one You.com organization Admin or Owner
* About 30 minutes on the calendar with your IdP administrator, a You.com Admin or Owner, and the assigned CSA

Optional, and useful if you want to shorten the call: create the SAML application in your IdP first and send the Metadata URL to the CSA through a secure channel.

## Configuration Flow

The CSA drives this sequence. The steps below are IdP-agnostic. Okta, Microsoft Entra ID, and other SAML 2.0 providers follow the same exchange. Label names in your IdP will differ.

### Create a SAML 2.0 Application in Your IdP

Create a SAML 2.0 app for You.com. Copy the application's Metadata URL. Send that URL to your CSA if you have not already.

### Exchange Metadata for You.com Endpoints

You.com returns an Entity ID and an Assertion Consumer Service (ACS) URL. Paste both into the SAML application. The CSA confirms the values during the call.

### Enable SCIM with the You.com Token

Turn on provisioning (often labeled API integration or SCIM). Paste the SCIM token You.com issues. Run the IdP's test connection if it has one.

Enable **Create**, **Update**, and **Deactivate** (or equivalent) for users.

Disable importing groups *from* You.com into the IdP. Group membership should flow IdP → You.com, not the reverse.

### Assign Groups and Push Them

Assign the IdP groups that should reach You.com to the application. Assignment is what grants sign-in. Then push those groups to You.com.

If you later change a group's membership or which groups are assigned, push again so You.com stays in sync.

> **Note**
>
> Assigning a group to the You.com app authorizes the users in that group to sign in. It does not grant organization-wide access to everyone in the IdP.

### Confirm Members on the Platform

Have the test Admin or Owner sign in to [you.com/platform](https://you.com/platform) through **SSO**, using their IdP credentials.

Open **Settings → Members**. The test user and other SCIM-created users should appear in the organization member list. If a user is missing, the CSA checks SCIM provisioning logs with you rather than a Platform import control.

> **Info**
>
> Older You.com admin docs described **Settings → Teams** and **Import from IdP**. Platform organizations manage people from **Settings → Members**. Roles and the invite path are on [Team Management](/docs/administration/team-management). This page does not document that older import path. If your tenant still shows it, ask your CSA whether it applies. Do not treat screenshots from an Okta-only runbook as the Platform UI.

## Best Practices

**Audit IdP assignments.** Only groups that should reach You.com belong on the app. Assignment is the seat-and-access control: people who are not assigned cannot sign in, even if they have a You.com account email on a covered domain.

**Manage access through groups**, not one-off user assignments, so joiners and leavers follow the same path as the rest of your directory.

**Watch provisioning logs** in the IdP after the first push, after group changes, and after offboarding. SCIM failures show up there before they show up as a login ticket.

## Troubleshooting

#### Login fails, or the user never reaches the Platform

Check IdP group assignment and whether SSO is enabled for that user's domain.

#### User is assigned in the IdP but never appears as a member

Check SCIM create/update, the token, the SCIM base URL, and provisioning logs.

#### User still has access after offboarding

Check SCIM deactivate. Confirm Deactivate users is on, then re-push or trigger a sync.

If the SAML handshake itself fails (ACS URL, Entity ID, certificate), stay on the configuration call or email [api@you.com](mailto:api@you.com) with the IdP error and the Metadata URL you exchanged.

## Related

#### [Account](/docs/administration/account)

Platform sign-up, including the SSO option on the login page.

#### [Team Management](/docs/administration/team-management)

Organization roles and the Settings → Members list SCIM fills.

#### [Get Help](/docs/support/get-help)

Contact [api@you.com](mailto:api@you.com), the support form, Discord, and status.you.com.

#### [API Keys](/docs/administration/api-keys)

Keys provisioned members create after they can sign in.