With SSO, your team signs in to the Kelu dashboard through your identity provider (IdP), such as Okta, Microsoft Entra ID or Google Workspace. Kelu picks the connection by email domain: anyone who signs in with an @acme.com address is sent to the IdP you registered for acme.com.
Google and GitHub sign-in work on every plan. OIDC and SAML connections need the Enterprise plan. Only workspace owners and admins can set them up.

Set up OIDC

1

Create an app in your IdP

Register a web application. Set its redirect URI to https://app.kelu.dev/api/v1/auth/sso/callback. Copy the issuer URL, client ID and client secret.
2

Add the connection in Kelu

Go to Settings → SSO. Fill in Provider Name, Email Domain (for example acme.com), Issuer URL, Client ID, Client Secret and Role for new members. Click Add SSO Connection.
3

Verify your domain

Add the TXT record shown on the page to your DNS. The name is _kelu-verification.<your-domain>. Then click Verify domain. DNS changes can take a few minutes.
4

Test it

Sign out. On the login page, click Sign in with SSO, enter a work email on your domain, and click Continue with SSO.
Sign-in stays closed until the domain is verified.

Set up SAML 2.0

The dashboard form creates OIDC connections only. SAML connections are created through the API.
1

Create a SAML app in your IdP

SettingValue
ACS / Reply URLhttps://app.kelu.dev/auth/sso/saml/acs
SP Entity ID / Audiencehttps://app.kelu.dev/saml/metadata
NameID formaturn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
Copy the IdP’s SSO URL and signing certificate (PEM or plain base64). A metadata URL cannot replace the SSO URL.
2

Create the connection

curl -X POST https://app.kelu.dev/api/v1/workspaces/$WORKSPACE_ID/sso \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "protocol": "saml",
    "provider": "Okta",
    "domain": "acme.com",
    "idp_sso_url": "https://acme.okta.com/app/…/sso/saml",
    "idp_certificate": "-----BEGIN CERTIFICATE-----…",
    "default_role": "user"
  }'
3

Verify the domain and test

Open Settings → SSO. Add the TXT record, click Verify domain, then sign in with Sign in with SSO.

Options

OptionWhat it does
Role for new membersThe role someone gets the first time they sign in through SSO: User (chat only, the default) or Member (can also manage knowledge bases). Existing members keep their role. Change anyone’s role on the Team page.
Require SSOTurns off password sign-in, password reset and Google/GitHub sign-in for everyone on the domain. Available after the domain is verified. The workspace owner keeps password access, so an IdP outage cannot lock you out. Turn it on after you have signed in through SSO once.
To change the issuer, client secret or certificate, delete the connection and add it again. One email domain can belong to only one workspace. When you delete a connection, people who joined through SSO have no Kelu password. They can use Forgot password or Google/GitHub sign-in. For who can see which knowledge bases, see roles and permissions.

Troubleshooting

MessageFix
No SSO connection is configured for that email domainCheck the email address. Subdomains need their own connection.
Your admin has not finished verifying this domain yetAdd the TXT record and click Verify domain.
Your identity provider returned an address outside this connection’s domainThe IdP sent an email on a different domain. One connection covers one domain.
That sign-in link has expired or was opened in a different browserThe sign-in took more than 10 minutes, or started in another browser. Start again.
SAML sign-in fails after it used to workYour IdP’s signing certificate probably changed. Delete the connection and create it again with the new certificate.