# IDP and SSO

The **IDP and SSO** page connects the organization to an identity provider for sign-in and membership management. Open it from **Organization settings > Identity > IDP and SSO** in the dashboard.

## Access requirements

<Callout type="info">
  Viewing this page requires the `org:read` scope, so both default Admin and Member roles can see it. Configuring SSO or Directory Sync requires the `org:admin` scope, held by Admins only, and the features are entitlement-gated by plan. Roles and scopes are managed in [Roles & Permissions](/docs/ai-control-plane/org-admin/roles-and-permissions).
</Callout>

## Identity cards

The page shows an **Identity** heading with two cards.

The **Single Sign-On** card lets the team set up Single Sign-On (SSO) to sign in to Speakeasy with the organization's identity provider. When SSO is active, the card shows a **Connected** badge.

The **Directory Sync** card provisions members automatically from the identity provider. Roles map from IdP groups, so no manual invites or role assignments are needed.

## Configuring a connection

Each card has a **Configure** button. Its behavior depends on the current state:

- When the feature is already active, the button opens the admin portal for managing the connection.
- When the feature is available but not yet set up, the button enters the setup wizard at the matching step. See [getting started](/docs/ai-control-plane/getting-started) for the full wizard flow.
- When the feature isn't included in the current plan, the button contacts the team to enable SSO and Directory Sync.
