Skip to content
English
  • There are no suggestions because the search field is empty.

Setting up and managing single sign-on (SSO)

One login, one set of credentials — configure SSO once and manage everything from the same place afterward.

Single sign-on (SSO) authenticates your team through your existing identity provider (IdP) instead of a separate Toggl password. It works with any IdP that supports SAML2 — Okta, Google Workspace, Microsoft Entra ID, OneLogin, and others.

SSO is available on Premium and Enterprise plans. 

Why teams turn SSO on

Security

  • With SSO enforced, Toggl access runs entirely through your identity provider — no standalone password to leak, and anyone your IdP no longer recognizes loses access automatically.
  • New accounts can't be self-created under a domain that's already SSO-enabled; people only join when an admin invites them.
  • Activity logs cover the last three months, so you've got a trail to work from if login issues come up.

Less to manage day to day

  • Nobody needs a separate password for Toggl — it's the same credentials they already use elsewhere.
  • One domain can cover several workspaces at once (an admin still has to invite each person individually).
  • More than one admin can share responsibility for the SSO profile, so it's never resting on a single person.
  • New users can be created automatically the moment they first log in via SSO, instead of an admin adding them by hand.

How it fits together

  1. An Organization Admin builds an SSO profile for the team's domain, using details from their identity provider.
  2. Toggl's team reviews it to confirm the domain and admin status check out.
  3. Once approved, anyone on that domain sees a Company login (SSO) option, and profile admins can turn on the extra controls covered later in this guide.

Building your SSO profile

You'll need Organization Admin access, and Toggl needs to be reasonably confident you own the domain you're registering.

Step 1 — Find the SSO section
Open the Admin Console and go to single sign-on, or use this direct link.

Step 2 — Start a new profile


Click + Create SSO profile, then fill in three sections:

  • Profile configuration — a name for the profile (useful once you have more than one) and the domain your team logs in with (e.g., organization.com for jane@organization.com).

  • Integration details — copy these values into your IdP's own setup page. Two things to get right on the IdP side: set the Unique User Identifier to the user's email, and set the SAML signing option to Sign SAML response.

    Need provider-specific steps? See: Setting up SSO for Okta · Setting up SSO for Google Workspace · Setting up SSO for Entra ID · Setting up SSO for OneLogin Note: If your users should start the login flow from your side rather than from accounts.toggl.com (Identity Provider–initiated login), append ?toggl_product=focus to the ACS URL

  • Identity provider information — pull these from your IdP. Either paste a metadata URL, or fill in the sign-in URL, entity ID, and X.509 certificate individually. Using more than one IdP for the same domain? Add another configuration and name each one clearly, since users will choose between them at login.
  • Configure Profile Settings — Choose if you want to enforce SSO-only login, disable user's from creating private organizations, and assign more admins to manage SSO. 

Step 3 — Submit
Click Submit for review.

What happens during review

Toggl checks two things: that you're an Organization Admin on a plan that includes SSO, and that you have a legitimate claim to the domain. This usually takes under two business days, and you'll get an email either way:

  • Approved — the profile goes live. Test your login, connect it to a workspace for auto-creation (below), or adjust the settings in the next section.
  • Not approved — it reverts to Draft with a reason listed on the page. Fix it and resubmit any time.

Managing an approved profile

Once live, open the SSO profile from Manage SSO profiles and scroll to its settings to adjust any of the following:

Enforce SSO-only login
Restricts that domain to SSO exclusively — no email/password, Google, or Apple login. New signups from that domain also get blocked outside of an admin invite. You can whitelist specific people to bypass this; profile admins are whitelisted automatically.

Add additional admins
Gives other team members full control over the profile — editing, enabling, disabling, or assigning it to workspaces. Anyone you add is whitelisted like the original creator, and can also remove other admins, including you.

Activity logs
Found at the top right of the SSO profile page — a record of everything that's happened on this profile over the last three months. Useful first stop when troubleshooting a login issue.

Automatic user creation
Off by default. When turned on for a workspace, anyone logging in via SSO for the first time gets a Toggl account created automatically and added to that workspace — no manual invite needed.

A few things worth knowing before you turn this on:

  • It only creates accounts — it won't remove anyone automatically.
  • It only fires on SSO logins; someone trying another method won't get an account made for them this way.
  • Since it can grow your team size, it may affect your subscription cost.

To enable it, you'll need to be an admin of both the SSO profile and the organization the workspace belongs to:

  1. Go to Admin Console → Single Sign On.
  2. Find the SSO profile in the list and toggle it on.
  3. Confirm — new users will be added automatically on their next SSO login.

Updating a certificate

If your IdP's certificate expires or rotates, you don't need to rebuild the profile:

  • Metadata URL configured? Just make sure the current URL is entered — Toggl pulls the updated sign-in URL, entity ID, and certificate automatically.
  • No metadata URL? Click the Edit (pencil) icon on the profile, uncheck Use metadata URL if needed, and upload or paste the new certificate.

No Edit option showing? You'll need Organization Admin permissions.

Adding more domains

Need SSO on another domain? Click + New SSO profile and repeat the setup — your SSO profiles page will list all of them together.