Enterprise SSO
under review
M
Michael (Driverforge)
For teams that manage driver development through a corporate identity provider, Anvil would support signing in with SAML 2.0 or OIDC. Members of an organization would authenticate with their company credentials — Okta, Azure AD, Google Workspace, OneLogin, or any other SAML/OIDC-capable provider — rather than with a separate Anvil password. Existing Anvil identities link to the corporate directory, so your team doesn't maintain two sets of logins.
When SSO is required for an organization, joining and leaving follow the normal employee lifecycle. A new hire added to your IdP's Anvil group gets access to the org the first time they sign in. Someone who leaves loses access at the same moment their company account is deactivated, with no separate step to remove them from Anvil. Contractors, consultants, and anyone else who comes and goes is handled by whatever rules already govern access to your other tools.
SSO can be set to optional (members can sign in either way) or required (SSO is the only path into the org). Session duration is configurable per organization so policies around re-authentication match the rest of your internal tooling. Users who belong to more than one org — for example, an employee of one Anvil customer who also helps out a partner — keep a single Anvil identity and pass through the right SSO check when they switch between them.
What we're thinking:
- SAML 2.0 and OIDC support
- Per-organization configuration by an admin, with a test-configuration step before going live
- Optional or required SSO enforcement
- Configurable SSO session duration
- Just-in-time provisioning so new employees don't need to be pre-invited
- Attribute mapping (name, email, optionally group → role)
- Audit logging of SSO sign-ins and config changes
Help us shape this:
- Which IdP does your team use, and do you already rely on it for other developer tools?
- Do you need SSO to be required for your org, or is optional SSO enough?
- Would you want group-based role assignment (e.g. an "Anvil Admins" group in your IdP mapping to admin access) from day one, or is that a later refinement?
M
Michael (Driverforge)
updated the status to
under review