---
title: "Directory"
description: "Connect your identity provider for single sign-on, and verify the email domains its people sign in with."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Directory

In **IAM** > **Directory**, you connect your organization's identity provider, such as Okta, Microsoft Entra ID or Google Workspace, over OIDC or SAML 2.0, and verify the email domains its people use. People with an email address in a verified domain can sign in with SSO, and [SCIM provisioning](/iam/scim) can create and manage them.

Identity providers are managed in the console.

## Verified domains

A verified domain is an email domain your organization proved it owns by publishing a DNS TXT record. You list one or more email domains when you add an identity provider, and they're verified together.

A verified domain:

- Lets people with an email address in it sign in through the identity provider. Nobody can sign in through a provider until its domains are verified.
- Lets SCIM provision people with an email address in it. SCIM refuses everyone else.
- While SCIM is on, can't be invited: invitations to email addresses in it return `409` with `managed_by_scim`.

An email address in a subdomain of a verified domain counts too: verifying `example.com` covers `ada@eu.example.com`.

The **Directory** page shows each provider's status: **Verified** or **Domain not verified**. The API's [GetScimConfiguration](/orgs-api/scim/GetScimConfiguration/) returns your organization's verified domains in `verifiedDomains`.

## Permissions

| Action | Allows | Managed policies |
| --- | --- | --- |
| `ssoProviders.list` | See identity providers, their domains and verification status | ReadOnlyAccess, IAMFullAccess |
| `ssoProviders.create` | Add identity providers | IAMFullAccess |
| `ssoProviders.verifyDomain` | Verify a provider's domains | IAMFullAccess |
| `ssoProviders.update` | Change a provider's group mapping | IAMFullAccess |
| `ssoProviders.delete` | Delete identity providers | IAMFullAccess |

`ssoProviders.update`, `ssoProviders.verifyDomain` and `ssoProviders.delete` can be scoped to one provider by its resource name, `ezgh::org_…:sso_…`.

## Add an identity provider

1. Open **IAM** > **Directory** and select **Add identity provider**.
2. Choose the **Protocol**, **OIDC** or **SAML 2.0**, and enter the **Email domains**, separated by commas: `example.com, example.org`.
3. Enter your identity provider's details:
   - OIDC: the **Issuer URL**, **Client ID** and **Client secret**. **Authorization endpoint** is optional; set it only if browsers reach your provider at a different address than the issuer.
   - SAML 2.0: the **SSO URL** and the **IdP metadata XML**.
4. Optionally, map groups at your identity provider to groups in your organization. See [Group mapping](#group-mapping).
5. Review, then select **Add provider**.

The console then shows what to configure at your identity provider: the **Redirect URI** for OIDC, or the **Entity ID (audience)**, **ACS URL** and **SP metadata** for SAML. They're also on the provider's **Setup** tab.

## Verify a domain

1. Open the provider under **IAM** > **Directory** and select the **Domain verification** tab.
2. At your DNS host, publish a TXT record for each domain the console lists, with its **Name** and the **Value**:

   | Type | Name | Value |
   | --- | --- | --- |
   | `TXT` | `_better-auth-token-sso_k3f9a0x2m7qp.example.com` | The value the console shows |

   The name is `_better-auth-token-`, the provider ID, a dot and the domain. Every domain of the provider uses the same value.
3. Once the records are published, select **Verify domain**.

Every listed domain must have a matching TXT record. If one doesn't, verification fails with `No matching TXT record found for <domain> yet` and no domain is verified. DNS changes can take time to be visible; select **Verify domain** again later. If the console says the verification token expired, delete the provider and add it again.

## Sign in with SSO

People sign in at `https://login.ezghcloud.com/sign-in/sso` with their work email address, or select **Sign in with SSO** on the sign-in page. Someone who isn't in your organization yet joins it the first time they sign in. Signing in is refused when:

- Their account already belongs to another organization.
- An administrator removed them from your organization. They can sign in with SSO again once they're invited back.
- SCIM is on and your identity provider hasn't provisioned them.
- Your identity provider suspended their account over SCIM.

## Group mapping

Group mapping puts people in your organization's groups based on the groups your identity provider sends.

- **Groups claim or attribute** names the OIDC claim or SAML attribute that lists a person's groups. The default is `groups`.
- Each mapping pairs a group name at your identity provider with a group in your organization. **Map everyone to a group** adds everyone who signs in through the provider to a group.
- On every sign-in, memberships from the mapping are added when the identity provider lists the group, and removed when it no longer does. Memberships added by hand stay.
- Without a mapping, people join with no access until someone adds them to a group or attaches policies to them.
- While SCIM is on, sign-in doesn't change group memberships. SCIM manages provisioned groups instead.

To change the mapping, open the provider's **Group mapping** tab and select **Edit mapping**. Changes apply from each person's next sign-in.

## Delete an identity provider

Open the provider under **IAM** > **Directory**, select **Delete**, and confirm. People in its domains can no longer sign in with SSO. Their accounts and group memberships stay. Its domains are no longer verified unless another provider lists them, so SCIM stops provisioning people in them.

## Limits

| Limit | Value |
| --- | --- |
| Email domains | One or more per provider, such as `example.com`. You can't change a provider's domains; delete it and add it again. |
| Identity providers added by one user | 10 |
| Identity provider URLs | Public `https` URLs |
| SAML metadata | 102,400 bytes |
| Group mappings per provider | 100 |
| Group name at your identity provider | 256 characters |
| Groups claim or attribute | 256 characters: letters, digits, `_`, `:`, `/`, `.` and `-` |

Source: https://docs.ezghcloud.com/iam/directory/index.mdx
