Skip to main content
Tightknit supports enterprise Single Sign-On (SSO) to integrate with your organization’s identity provider, enabling seamless and secure authentication for your community members.

Supported Protocols

Tightknit supports the following industry-standard SSO protocols:
  • OIDC (OpenID Connect) - Modern authentication protocol built on OAuth 2.0
  • SAML 2.0 - Enterprise-grade XML-based authentication standard
  • Token-based JWT - Custom integrations for IdP-initiated flows

Supported Authentication Flows

SP-Initiated Flow

Users start at your Tightknit community and are redirected to your identity provider to authenticate. After successful authentication, they are returned to Tightknit and logged in automatically.

IdP-Initiated Flow

Users start at your identity provider portal and can access your Tightknit community directly from there. They land on Tightknit already authenticated without needing to sign in again.
IdP-initiated SSO requires Token-based JWT configuration. Please contact support to enable this feature.

Supported Identity Providers

Tightknit works with major enterprise identity providers, including:
  • Google Workspace
  • Microsoft Azure AD / Entra ID
  • Okta
  • Auth0
  • OneLogin
  • And other OIDC/SAML-compliant providers

Getting Started

To set up SSO for your organization, contact [email protected] with:
  • Your company name
  • Your email domain
  • Your identity provider
Our team will guide you through the configuration process and provide the necessary technical details for your IT team to complete the integration.

Connecting SSO to an existing account

When a member signs in with SSO using an email address that already has a Tightknit account created another way — an email sign-in code, or a Google, GitHub, or Slack login — Tightknit does not merge the two automatically. Trusting the identity provider’s word alone would let a misconfigured or compromised IdP claim someone else’s account. Instead, the member is sent a confirmation email:
  1. They sign in with your identity provider as usual.
  2. The login page tells them to check their email, and Tightknit emails the asserted address a confirmation link naming your community and the identity provider.
  3. Opening the link shows a confirmation page. Nothing changes until they select Connect — simply opening the email is not enough.
  4. After confirming, they return to the login page and sign in with SSO again, which now succeeds.
This happens once per member, per identity provider. Afterwards, SSO sign-in works normally. The confirmation email is always required when the asserted address belongs to someone who is not yet an established member of your community. An invitation on its own is never enough for your identity provider’s claim to attach to an existing Tightknit account. A Tightknit account can belong to several communities, so only the person who can open that mailbox may connect it to yours.
Confirmation links are single-use and expire after 10 minutes. If a member misses the window, they can start again by signing in with SSO — a new link is sent. A member who never confirms keeps their existing sign-in methods and loses no access.
Administrators can see this activity in Workspace > Audit under the Authentication section: SSO link confirmation sent, SSO link confirmed, SSO link expired, and SSO link rate-limited.

Troubleshooting

If you encounter issues with SSO authentication, please contact [email protected] with:
  • A description of the issue
  • Any error messages you see
  • Screenshots if available
Our support team will help resolve any configuration issues.