# Sign-in and security

Each person chooses how they sign in, and an organization Owner can connect the company's identity provider so that people at your email domain sign in through it.

## Before you start

- Passkeys and connected accounts are personal: open the account menu, then **Security**.
- Single sign-on needs the Owner organization role.

<PlanAvailability feature="Sso" plan="Scale" />

## Sign-in methods

The sign-in page offers:

- **Email address** and **Password**;
- **Sign in with a passkey**;
- **Sign in with** GitHub or Google, where the deployment offers them.

## Add a passkey

1. Open **Security** and, under **Passkeys**, select **Add passkey**.
2. Enter a **Device name**, then confirm with your fingerprint, face or device PIN.

Each passkey shows when it was added and last used. **Remove** stops it working on that device. A browser without passkey support says so.

## Connected accounts

**Connected accounts** lists the GitHub or Google accounts you can sign in with. **Disconnect** removes one. If it is the only way you can sign in, Costfluent refuses until you set a password or add a passkey.

## Connect single sign-on

Open **Settings**, then **Single sign-on**.

1. Under **Connect an identity provider**, enter the **Email domain** whose people should sign in through your provider.
2. From your provider, enter the **Discovery URL** (the OpenID Connect discovery document, usually ending in `/.well-known/openid-configuration`), the **Client ID** and the **Client secret**. The secret is stored in a secret store and never shown again.
3. Choose the **Default role** for people Costfluent creates: Viewer or Editor. Owner cannot be granted this way.
4. Turn on **Create accounts automatically** if a person signing in for the first time should get an account at the default role.
5. Select **Save connection**.

## Verify the domain

1. Select **Show the TXT record** and publish it in your domain's DNS.
2. Select **Verify domain**. If the record is not found yet, wait for DNS to propagate and try again.

## Enable and enforce

- **Enabled** lets people at the domain sign in through your provider.
- **Require single sign-on** makes everyone sign in through it. Every other session is ended, except those of break-glass Owners, and the product says how many sessions ended.

**Remove connection** sends people at the domain back to signing in with a password.

## Related

- [Users, teams and roles](/admin/users-teams-and-roles)
- [Audit log](/admin/audit-log)
