Supported Protocols
Tightknit supports the following industry-standard SSO protocols:- OIDC (OpenID Connect) - Modern authentication protocol built on OAuth 2.0
- SAML 2.0 - Enterprise-grade XML-based authentication standard
- Token-based JWT - Custom integrations for IdP-initiated flows
Supported Authentication Flows
SP-Initiated Flow
Users start at your Tightknit community and are redirected to your identity provider to authenticate. After successful authentication, they are returned to Tightknit and logged in automatically.IdP-Initiated Flow
Users start at your identity provider portal and can access your Tightknit community directly from there. They land on Tightknit already authenticated without needing to sign in again.IdP-initiated SSO requires Token-based JWT configuration. Please contact
support to enable this feature.
Supported Identity Providers
Tightknit works with major enterprise identity providers, including:- Google Workspace
- Microsoft Azure AD / Entra ID
- Okta
- Auth0
- OneLogin
- And other OIDC/SAML-compliant providers
Getting Started
To set up SSO for your organization, contact [email protected] with:- Your company name
- Your email domain
- Your identity provider
Connecting SSO to an existing account
When a member signs in with SSO using an email address that already has a Tightknit account created another way — an email sign-in code, or a Google, GitHub, or Slack login — Tightknit does not merge the two automatically. Trusting the identity provider’s word alone would let a misconfigured or compromised IdP claim someone else’s account. Instead, the member is sent a confirmation email:- They sign in with your identity provider as usual.
- The login page tells them to check their email, and Tightknit emails the asserted address a confirmation link naming your community and the identity provider.
- Opening the link shows a confirmation page. Nothing changes until they select Connect — simply opening the email is not enough.
- After confirming, they return to the login page and sign in with SSO again, which now succeeds.
Confirmation links are single-use and expire after 10 minutes. If a member misses the window, they can start again by signing in with SSO — a new link is sent. A member who never confirms keeps their existing sign-in methods and loses no access.
SSO link confirmation sent, SSO link confirmed, SSO link expired, and SSO link rate-limited.
Troubleshooting
If you encounter issues with SSO authentication, please contact [email protected] with:- A description of the issue
- Any error messages you see
- Screenshots if available

