> ## Documentation Index
> Fetch the complete documentation index at: https://docs.allgoodhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring SSO and verifying your domain

> Configure allGood to use your enterprise IdP, and verify ownership of your domain.

## Prerequisites

* You'll need an IT administrator who can configure a SAML SSO connection to your identity provider, and/or modify DNS records to verify ownership of your domain.
* You'll need to reach out to your allGood support team for an admin setup link for SSO. \
  It should begin with: `https://setup.allgoodhq.app/init?`

<Frame caption="The admin portal will lead you through two setup flows: one for domain verification, and one to configure SAML SSO.">
  <img src="https://mintcdn.com/allgoodtechnologyinc/ehJX4q8SzeGZVVYO/images/image-7.png?fit=max&auto=format&n=ehJX4q8SzeGZVVYO&q=85&s=36b816aceea3d4144f77ac87e445b150" alt="Image" width="880" height="372" data-path="images/image-7.png" />
</Frame>

## Domain Verification

<Steps>
  <Step title="Open the &#x22;Verify your Domain&#x22; flow in the setup portal." />

  <Step title="Enter your organization's domain name.">
    If your org uses multiple domains, enter the domain name that can be found after the `@` in your email address.

    <Frame caption="Enter the domain that your organization uses for email.">
      <img src="https://mintcdn.com/allgoodtechnologyinc/ehJX4q8SzeGZVVYO/images/image-9.png?fit=max&auto=format&n=ehJX4q8SzeGZVVYO&q=85&s=ebccaae76a7a73e2ce7feba456e84802" alt="Image" width="902" height="498" data-path="images/image-9.png" />
    </Frame>
  </Step>

  <Step title="Follow the instructions onscreen.">
    The admin portal will identfy your DNS provider based on the domain you supply, and will give you detailed instructions on how to add a DNS record verifying your ownership of that domain in allGood.
  </Step>
</Steps>

## SSO Setup

<Steps>
  <Step title="Open the &#x22;Configure Single Sign-On&#x22; flow in the setup portal." />

  <Step title="Find your identity provider in the list and select it.">
    If you don't see your particular IdP in the list of options, you can continue with "Custom SAML" or "Custom OIDC" at the bottom of the screen.

    <Frame caption="Find your IdP in the list, and select it.">
      <img src="https://mintcdn.com/allgoodtechnologyinc/ehJX4q8SzeGZVVYO/images/image-11.png?fit=max&auto=format&n=ehJX4q8SzeGZVVYO&q=85&s=feb8c88fab418bb6f052762e44899b50" alt="Image" width="738" height="890" data-path="images/image-11.png" />
    </Frame>
  </Step>

  <Step title="Follow the instructions onscreen.">
    The admin portal will give you specific, step-by-step instructions on how to configure SSO to allGood from your IdP.
  </Step>
</Steps>

## Testing SSO

Once you have completed the domain verification and set up SSO, you'll be able to sign in to `allgoodhq.app` with an email address from your organization.

<Frame caption="Enter an email from your org in the &#x22;Email&#x22; box, and click &#x22;Continue&#x22;.">
  <img src="https://mintcdn.com/allgoodtechnologyinc/ehJX4q8SzeGZVVYO/images/CleanShot2026-03-04at17.29.00@2x.png?fit=max&auto=format&n=ehJX4q8SzeGZVVYO&q=85&s=d4d0d431a511f0fabcbc98b538ea7753" alt="Clean Shot 2026 03 04 At 17 29 00@2x" title="Clean Shot 2026 03 04 At 17 29 00@2x" className="mx-auto" style={{ width:"48%" }} width="966" height="1118" data-path="images/CleanShot2026-03-04at17.29.00@2x.png" />
</Frame>

This will redirect you to your organization's sign-in page.

## Frequently Asked Questions

<AccordionGroup>
  <Accordion title="How long does the SAML Integration take to go live?">
    Depending on your identity provider, there might be a delay in propagating the relevant data and the SAML login could take up to 24 hours to become live. Please check with your Identity Provider for details.
  </Accordion>

  <Accordion title="Does the domain verification and the Identity Provider have to be valid?">
    Yes, since we only allow logins from the domain you have verified, please make sure that your IDP and Domain are both correctly configured. If you're experiencing issues verifying your domain, reach out to allGood support—we can verify it manually if the DNS approach won't work in your environment.
  </Accordion>

  <Accordion title="How long can the process of Domain Verification take?">
    Due to standard DNS propagation, this process can also take up to 4 hours, however, with most DNS providers, this should likely only be a few minutes.

    <Frame caption="The admin portal will keep checking your DNS records for however long the changes take to propagate.">
      <img src="https://mintcdn.com/allgoodtechnologyinc/ehJX4q8SzeGZVVYO/images/image-12.png?fit=max&auto=format&n=ehJX4q8SzeGZVVYO&q=85&s=4df225266d527b8d414eb2ad51346377" alt="Image" className="mx-auto" style={{ width:"92%" }} width="812" height="292" data-path="images/image-12.png" />
    </Frame>
  </Accordion>
</AccordionGroup>
