Introduction
Laravel Cloud supports single sign-on (SSO) through Security Assertion Markup Language (SAML) 2.0 and OpenID Connect (OIDC). With SSO, members of your organization can authenticate through an identity provider such as Okta, Auth0, Microsoft Entra ID, or Google Workspace instead of managing separate Cloud credentials. You configure SSO at the organization level. Once enabled, members of your organization can sign in to Cloud through your identity provider. Cloud continues to manage organization membership and roles.Configuring SSO
Setting up SSO begins by enabling it for your organization and verifying that you own the domain your members sign in with.1
Enable single sign-on
Navigate to your organization’s Settings > General page and toggle Enable single sign-on. This opens the single sign-on configuration modal, where you first verify your domain and then configure your identity provider. Only Admins can configure SSO.
2
Verify your domain
Under Domain verification, enter your organization’s domain and click Add domain. You can add multiple domains if members use email addresses from multiple domains.
3
Add DNS records
Add the DNS records Cloud provides to your domain. Cloud automatically verifies your domain after the records propagate, which may take a few hours. You may close the modal and return later without losing progress.
4
Configure your identity provider
Once Cloud has verified your domain, complete the Identity provider configuration step to connect your identity provider. Each identity provider is different, so follow the steps presented in the SSO flow for your provider.
Signing in with SSO
Once SSO is enabled, members of your organization can authenticate in two ways:- From your identity provider: Members can launch Cloud directly from their identity provider’s application dashboard.
- From Cloud: Members can choose the SSO option on the Cloud login page and enter their work email address. Cloud will redirect them to your identity provider to authenticate.

