Tapper
Search docs...
⌘K
SupportDashboard

Single Sign-On

Set up OpenID Connect for your workspace - issuer, client, email domains, domain verification, and the three switches that decide who can get in.


Single sign-on lets your team sign in to Tapper with your own identity provider. Tapper speaks OpenID Connect, so Okta, Microsoft Entra, Ping and Auth0 all work.

Owners and admins set it up in Settings → Single sign-on. Each workspace has one connection.

Before You Start

Create a web application in your identity provider and note its issuer, client ID and client secret. The exact place to find each one is in Set up your identity provider.

That app also needs a few values from Tapper - the callback URL, the sign-out URL, the sign-in link for your app tile and the scopes. They are all on the settings page itself, under Set up your identity provider, each with a copy button, and listed again in Set up your identity provider.

Fill In the Connection

1
Provider

Fixed at OpenID Connect. Tapper reads your provider's discovery document, so there is nothing else to pick.

2
Issuer URL

The issuer URL from your provider. It must be an https address with no query string, no fragment and no credentials.

3
Client ID

From the web application you created in your provider.

4
Client secret

Stored encrypted. Tapper never shows it again after you save. On a later edit, leave it empty to keep the stored one, or type a new one to replace it. Once a domain is verified, only the workspace owner can change the issuer URL, client ID or client secret. Admins can do everything else.

5
Email domains

Anyone whose work email is on one of these domains is sent to your provider. A domain belongs to one workspace only. Type the domain and click Add domain.

6
Role for new members

People who arrive through your provider join with this role. Owners are never created this way.

Save the connection.

Test the Connection

Click Test connection. Tapper reads the discovery document and the signing keys from the issuer you entered and shows what it found. It does not sign anyone in, so it is safe to run at any point.

Verify Your Domains

A domain does nothing until you prove you own it. Until a domain is verified, nobody is sent to your provider and nothing is enforced for it.

1
Read the record

Each saved domain shows a TXT record to publish, in the form _tapper-sso.yourcompany.com TXT tapper-sso-verification=<your token>.

2
Publish it

Add that TXT record at your DNS provider.

3
Check it

Come back and click Check DNS records. A verified domain shows Verified; one that is still waiting shows Not verified yet.

Verification proves the domain is yours, so nobody else can point your people's sign-in at their own provider. Once a domain is verified it stays verified - removing the TXT record later does not lock your team out. Removing the domain from the connection is the way to stop it.

Once a domain is verified, your team has a direct link to your provider - no password form on the way:

https://app.tapper.ai/sso/<your-domain>

You do not have to type it out. Settings › Single sign-on shows the ready-made link next to each verified domain, under Share this sign-in link with your team, with a copy button.

For example https://app.tapper.ai/sso/acme.com. Put it in your intranet, your onboarding notes or your provider's app tile. Anyone who opens it sees the page with your domain already filled in and one button - Continue to acme.com's sign-in - and pressing it hands them to your identity provider; they land in Tapper when they come back.

The button is deliberate. A page that redirected the moment it was opened could be used to start a sign-in nobody asked for - a link dropped in a chat, or loaded invisibly by another site - so the last step is always a press by the person signing in.

The same page without a domain, https://app.tapper.ai/sso, asks for a work email or company domain first. There is a Use single sign-on link to it on the sign-in page.

The link only works for a domain that is verified. Before that it says the domain is not set up for single sign-on and offers the password form instead.

Who Can Get In

Three switches on Settings › Single sign-on control access. Each one is independent. With all three off, nobody at your domains is affected.

  • Create accounts automatically. Someone at a verified domain who signs in through your provider and is not in this workspace yet joins it with the role you chose, and gets a Tapper account if they do not have one. Someone you removed from the workspace is never added back this way, and nobody joins while the workspace has no seats left on its plan. When it is off, only people you invite can get in through your provider.
  • Require SSO for this workspace. People at your verified domains can open this workspace only after signing in through your provider. Anyone already signed in with a password or Google is asked to continue with your company login once when they open it. Their other Tapper workspaces are not affected. This switch stays disabled until at least one person has signed in successfully through your provider.
  • Lock @yourcompany.com accounts to this workspace (the label shows your own domains). Passwords and Google stop working for people at your verified domains, both for signing in and for creating an account, and those accounts can use only this workspace. Their memberships in other workspaces are kept, but those workspaces refuse them while the lock is on, and turning the lock off opens them again. If Create accounts automatically is off, people at those domains who are not in this workspace yet cannot use Tapper until you invite them. Before the lock turns on, Tapper counts how many of those accounts also belong to other workspaces and how many other workspaces that is, and you confirm those numbers. If the numbers change before you save, Tapper shows the new ones and asks again. The switch stays disabled until every domain on the connection is verified and at least one person has signed in successfully through your provider. While the lock is on you cannot add a domain: turn the lock off, add and verify the domain, then turn the lock on again.

If something goes wrong later, turn the switch off again - that is the way back.

Enforcement follows the email domain, not the person. A guest on another domain in the same workspace keeps signing in the way they did before.

Removing It

Remove the connection from the same page. People go back to signing in with a password or Google.