packages/kilo-docs/pages/collaborate/enterprise/sso.md
Kilo Enterprise lets your organization securely manage access using Single Sign-On (SSO). With SSO enabled, team members can sign in to Kilo using your company's existing identity provider, such as Okta, Github, Google Workspace, etc.
{% callout type="warning" %} IDP-initiated logins are not currently supported. Users must navigate to the Kilo Web App to log in. Logging in directly from your identity provider's dashboard is not supported at this time. {% /callout %}
You’ll need:
Find the Single Sign-On (SSO) Configuration panel, and click "Set up SSO": {% image width="822" height="288" alt="Set-up-SSO screen" src="https://github.com/user-attachments/assets/b6ca5f83-4533-4d41-bcb1-0038b645c030" /%}
Fill in your contact information and someone from our team will reach out soon to help you configure SSO.
Once the Kilo team has enabled SSO for your organization, your named admin will get an email from WorkOS to configure SSO.
{% callout type="warning" %} Save domain policy for last.
If you configure domain policy before setting up SSO, you may lock users out of Kilo. {% /callout %}
Your admin will need to use the WorkOS link to:
Find the Metadata in your Identity Provider and apply that configuration in WorkOS.
Copy the Service Provider details (Entity ID, ACS URL, and Metadata) from the WorkOS dashboard and apply them in your Identity Provider.
After enabling SSO: