# Single Sign-On (SSO) Support

Ango Hub supports Okta Single Sign-On (SSO) for our paid customers. Please contact iMerit through our [Contact Us](https://imerit.net/contact-us/) page for more information on how to become a paid customer.

All users (free and paid) may use Google SSO to sign up and log in to Ango Hub. Google SSO is, however, not available in private cloud and on-premise deployments of Ango Hub.

## [​](https://docs.encord.com/platform-documentation/Other/encord-sso#requirements)Requirements <a href="#requirements" id="requirements"></a>

To enable SSO for your organization, you must have an identity provider that supports [OpenID Connect](https://openid.net/developers/how-connect-works/).

## How to set up SSO on Ango Hub using [Okta](https://okta.com/) <a href="#set-up-sso-using-okta" id="set-up-sso-using-okta"></a>

1. From your Okta console, enter the Directory -> People section and ensure everyone who needs access to Ango Hub has been added to this list.\ <br>

   <figure><img src="https://3895963154-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTcOUG6rfWxqGM0N4db2P%2Fuploads%2FbiKXJJvWe5GhXUptG7cz%2Fimage.png?alt=media&#x26;token=42529972-7f2a-4cf6-943a-cf065b662957" alt=""><figcaption></figcaption></figure>
2. From the Applications -> Applications section, click on *Create App Integration* to create a new application. We will use this application to connect to Ango Hub.<br>

   <figure><img src="https://3895963154-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTcOUG6rfWxqGM0N4db2P%2Fuploads%2F99g448rLvqgbxFk9JyzL%2Fimage.png?alt=media&#x26;token=f631a64c-3679-4618-81c3-6dad2d06ea62" alt=""><figcaption></figcaption></figure>
3. From the dialog that appears, please select the following options and click on *Next.*<br>

   <figure><img src="https://3895963154-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTcOUG6rfWxqGM0N4db2P%2Fuploads%2FKSKiQF9xos0lSbIpiFkF%2Fimage.png?alt=media&#x26;token=27bdd778-ae7f-41d4-865f-8733c9d5955e" alt=""><figcaption></figcaption></figure>
4. You will be brought to the application settings form.\
   ![](https://3895963154-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTcOUG6rfWxqGM0N4db2P%2Fuploads%2Fsoa02BNutFKaR6opl1C8%2Fimage.png?alt=media\&token=48e15d2f-325e-428f-9fa8-e658de5e105d)
   1. *App Integration Name*: enter a name of your choice.
   2. *Sign-In Redirect URIs:* `https://imeritapi.ango.ai/v1/auth/oidc-callback`.
   3. *Sign-Out Redirect URIs*: `https://imeritapi.ango.ai/v1/auth/logout`<br>
   4. *Login Initiated by:* "Either Okta or App"
   5. *Application Visibility* toggle: on.
   6. *Login flow*: "Redirect to app to initiate login (OIDC Compliant)
   7. *Initiate login URI*: `https://imeritapi.ango.ai/v1/auth/oidc-login`
   8. In the *Controlled Access* section, choose who, from your organization, will be able to log into Ango Hub. If you wish for everyone in your Okta organization to have access to Ango Hub, select *Allow everyone in your organization to access*, and enable *Federation Broker* mode.
   9. Click on *Save*.
5. You will be redirected to the application information section. Please copy the following three pieces of information (highlighted: App ID, Secret, and User ID) and share them with the iMerit team. We will enable Okta SSO for your organization.<br>

   <figure><img src="https://3895963154-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTcOUG6rfWxqGM0N4db2P%2Fuploads%2FRBBnxz54VX8katVRHuXb%2Fimage.png?alt=media&#x26;token=bf17ca14-06db-42e2-a50c-1f623948bb19" alt=""><figcaption></figcaption></figure>

## How to Log In with SSO <a href="#log-in-with-sso" id="log-in-with-sso"></a>

If SSO has been enabled for your organization, in the login page, enter your email. You will be logged in automatically.
