Let your Enterprise team sign in to HeroUI Pro with SAML 2.0 or OpenID Connect.
Single Sign-On (SSO) lets people on your company email domain sign in to HeroUI Pro through your identity provider. It is included with the Enterprise plan.
SSO authenticates the person. Team invitations and roles still decide who belongs on the team and what they can do. Email, Google, and GitHub stay available.
If SSO is not on your plan, contact sales@heroui.pro to get Enterprise.
On the SSO page, enter a company name and create the company. The company holds the identity-provider connection and the domains you verify.

Choose OpenID Connect or SAML 2.0.
For SAML:
acme.com.email and displayName.
HeroUI then shows the ACS URL and service-provider metadata. Register those values with your identity provider so it can send signed SAML assertions back.
For OpenID Connect, save the issuer URL, client ID, and client secret instead. Register the redirect URI that HeroUI shows after you save.
Saving replaces the callback URLs. You will need to verify the domains and run a new test.
HeroUI issues a TXT record for each domain. Add it in DNS, wait a few minutes, then click Verify domains.
| Type | Name | Value |
|---|---|---|
| TXT | _heroui-sso.acme.com | The unique token shown in the dashboard |
Copy the name and value from the dashboard rather than typing them. Each exact domain is verified on its own. A subdomain such as eng.acme.com needs its own record.
Activate stays disabled until that test succeeds for the current connection.
After activation, share the company sign-in link from the same section.
Automatic joining stays unavailable until SSO is active. When you enable it, new users join the Pro team as members after SSO and two-factor authentication, without an invitation. An available seat is required.
Directory sync is not connected. Removing someone from your identity provider does not release their HeroUI seat. Existing members keep their role.
On the login page:
SSO does not change an existing member's role. If automatic joining is off, it also does not create a team seat — invite people from Members. If it is on, new users join when a seat is available.
Disable the connection before you replace metadata, rotate a secret, or change domains. Other sign-in methods stay available.
Delete company SSO if you want to remove the connection. You can set it up again later.
Verify domains does not succeed. Confirm each TXT name is _heroui-sso. plus the exact domain, and that the value matches the dashboard. DNS can take a few minutes.
Activate SSO is disabled. Finish a successful test with the owner account after the latest save. Saving the connection invalidates the previous test.
Continue with SSO does not work for a teammate. Their email domain must match a verified company domain, and the connection must be active.
You cannot open SSO settings. Only the team owner can create and manage the connection, and Enterprise must be active.
If you are still stuck, contact support@heroui.pro.