@acme.com address is sent to the IdP you registered for acme.com.
Google and GitHub sign-in work on every plan. OIDC and SAML connections need the Enterprise plan. Only workspace owners and admins can set them up.
Set up OIDC
Create an app in your IdP
Register a web application. Set its redirect URI to
https://app.kelu.dev/api/v1/auth/sso/callback. Copy the issuer URL, client ID and client secret.Add the connection in Kelu
Go to Settings → SSO. Fill in Provider Name, Email Domain (for example
acme.com), Issuer URL, Client ID, Client Secret and Role for new members. Click Add SSO Connection.Verify your domain
Add the TXT record shown on the page to your DNS. The name is
_kelu-verification.<your-domain>. Then click Verify domain. DNS changes can take a few minutes.Set up SAML 2.0
The dashboard form creates OIDC connections only. SAML connections are created through the API.Create a SAML app in your IdP
| Setting | Value |
|---|---|
| ACS / Reply URL | https://app.kelu.dev/auth/sso/saml/acs |
| SP Entity ID / Audience | https://app.kelu.dev/saml/metadata |
| NameID format | urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress |
Options
| Option | What it does |
|---|---|
| Role for new members | The role someone gets the first time they sign in through SSO: User (chat only, the default) or Member (can also manage knowledge bases). Existing members keep their role. Change anyone’s role on the Team page. |
| Require SSO | Turns off password sign-in, password reset and Google/GitHub sign-in for everyone on the domain. Available after the domain is verified. The workspace owner keeps password access, so an IdP outage cannot lock you out. Turn it on after you have signed in through SSO once. |
Troubleshooting
| Message | Fix |
|---|---|
| No SSO connection is configured for that email domain | Check the email address. Subdomains need their own connection. |
| Your admin has not finished verifying this domain yet | Add the TXT record and click Verify domain. |
| Your identity provider returned an address outside this connection’s domain | The IdP sent an email on a different domain. One connection covers one domain. |
| That sign-in link has expired or was opened in a different browser | The sign-in took more than 10 minutes, or started in another browser. Start again. |
| SAML sign-in fails after it used to work | Your IdP’s signing certificate probably changed. Delete the connection and create it again with the new certificate. |