Single sign-on and SCIM
Verify your domain, sign your team in through Okta, Entra ID, Google Workspace or any OpenID Connect or SAML provider, and provision users with SCIM.
coview never stores passwords: people sign in with Google, Microsoft, a 6-digit code emailed to them (valid 10 minutes), or your company's own identity provider. Everything on this page lives in Settings › Security & SSO and needs the Sign-in, SSO and security permission (owners and admins).
Domains and single sign-on with OpenID Connect are on the Business plan and higher; SAML 2.0 and user provisioning (SCIM) are on Enterprise.
1. Verify your domain
- Under Your domains, enter your company's domain (for example
yourcompany.com) and click Add domain. - Add the TXT record shown (Name and Value) where you manage DNS.
- Click Check now. DNS can take a few minutes; check again if it isn't there yet. A verified domain shows Verified with the date.
A workspace can verify up to 10 domains, and a domain can be verified by only one coview workspace. For each domain, New people join as decides what happens when someone with that address signs in without an invitation: Don't add them, or a seat as Agent, Viewer or Supervisor.
Ways to sign in switches Google, Microsoft, email codes and your SSO provider on or off for addresses in your verified domains. At least one must stay on.
2. Connect your provider
OpenID Connect
For Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud or any other OpenID Connect provider.
- Under Single sign-on, keep OpenID Connect selected.
- In your provider, register coview as a web app with the sign-in address shown (
https://api.coview.work/oauth/callback). - Back in coview, pick the Provider, and paste the Issuer URL, Client ID and Client secret. coview reads the provider's settings from the issuer when you save, and stores the secret encrypted; nobody can read it back.
- Click Connect provider, then Test sign-in.
SAML 2.0
- Under Single sign-on, choose SAML 2.0.
- In your provider (Okta, Entra ID, Google Workspace, OneLogin, JumpCloud or ADFS), add coview as a SAML app with the values shown: the Single sign-on URL (ACS), the Audience URI (SP entity ID) and the Metadata address. The Name ID is the person's email address.
- Paste the Identity provider issuer (entity ID), the Identity provider sign-in URL and the Signing certificate (PEM or base64).
- Click Connect provider, then Test sign-in.
coview checks every SAML response against the certificate you pasted, never against a key the response brings. Responses must be signed with SHA-256; encrypted assertions aren't accepted. People signing in through SAML need an address in one of your verified domains.
3. Decide who it applies to
- Require it for your verified domains: Google, Microsoft and email codes stop working for those addresses, so everyone goes through your provider.
- Create accounts on first sign-in: anyone your provider lets in gets a seat with the role you pick (Agent, Viewer or Supervisor).
People sign in from the coview sign-in page with Sign in with SSO and their work email. Disconnect removes the provider.
User provisioning (SCIM)
With SCIM, your identity provider (Okta, Entra ID, OneLogin or JumpCloud) adds people to the workspace, changes their names and email addresses, and deactivates or removes them when they leave. Roles stay in coview: groups from the provider aren't used.
- Under User provisioning (SCIM), click Turn on user provisioning.
- Copy the address shown and paste it as the SCIM base URL in your provider. It carries the token, so coview shows it only once. If the provider also asks for a token, enter anything.
- Choose the role under New people join as: Agent, Viewer or Supervisor.
- Deactivating a person in your provider disables their membership; deleting them removes it. Their coview account itself stays.
- The last active owner is never disabled or removed.
- Treat the address like a password. If it leaks, click Make a new address: the old one stops working at once.
- Turn off stops the provider syncing.
Changes made through SCIM, and changes to these settings, are written to the audit log.
A person from coview will help — send us a message, or book a demo and we'll walk through it with you.