SSO is available for organizations on Enterprise plans. Contact our sales team if you’d like to discuss enterprise options.
Requirements
- Your organization must be on an Enterprise plan
- You must be an organization admin to enable and configure SSO
- You must have a verified email address on your account
- Access to your domain’s DNS records (for domain verification)
- Admin access to your identity provider
Enabling SSO
SSO management lives on the members page of your organization settings:1
Open the SSO tab
While in your organization context, navigate to Settings > Members and select the SSO tab.
2
Click Enable SSO
Click Enable SSO. This adds a Security tab to your organization settings, where you (or your IT admin) can manage domains and identity provider connections.
Connecting Your Identity Provider
Once SSO is enabled, connect your identity provider from the Security tab:1
Open the Security tab
From the SSO tab, click Configure SSO to open the Security tab of your organization settings.
2
Add your email domain
Add the email domain your team signs in with (for example,
acme.com).3
Verify the domain with a DNS record
Publish the TXT record shown in the setup flow to your domain’s DNS. Verification usually completes within a few minutes of the record propagating.
4
Connect your identity provider
Follow the guided setup for your provider (Okta, Microsoft Entra ID, Google Workspace, or custom SAML) to exchange SAML metadata between OpenRouter and your IdP.
5
Test and activate
Test the connection with an account from your domain, then activate it. Active connections appear in the SSO tab.
Connection Statuses
Each connection in the SSO tab shows its domain, how it was created, and its current status:
Connections are labeled Self-serve connection when created through the Security tab, or Configured by OpenRouter when set up by our team on your behalf.
Automatic Group Provisioning
With an SSO connection in place, you can also sync groups from your identity provider and map them to OpenRouter workspaces, so workspace access is provisioned automatically. See SCIM Group Mappings.Frequently Asked Questions
Can I turn SSO off after enabling it?
Can I turn SSO off after enabling it?
Enabling self-serve SSO management for your organization is one-way. Individual connections can be disabled from the Security tab, and you can contact support@openrouter.ai for help with your SSO configuration.
Can I connect more than one domain?
Can I connect more than one domain?
Yes. Domains and connections are managed in the Security tab of your organization settings; each verified domain gets its own connection entry in the SSO tab.
Who can manage SSO?
Who can manage SSO?
Only organization admins can enable SSO and access the Security tab. Regular members won’t see the SSO management options.
I don't see the SSO tab — why?
I don't see the SSO tab — why?
The SSO tab is available to organization admins on Enterprise plans. If your organization’s SSO was configured directly by OpenRouter, reach out to support@openrouter.ai for changes.
Getting Help
- Setup assistance: Email support@openrouter.ai
- Enterprise plans: Contact our sales team to enable SSO for your organization