Skip to main content
You don’t need a separate Reagent password. Single sign-on is for Enterprise organizations that have set it up with Reagent’s team. If you’re setting up SSO for your organization, go to For IT Admins.

For Members

Before you start, you need:
  • The latest version of Reagent (0.15.1 or later). Download Reagent.
  • Your work email address, on your company’s email domain.
  • Your organization’s endpoint details from your IT team: the Endpoint URL, API key and Model ID. Reagent asks for them after you sign in.
You don’t need a Reagent account first. If you already have one with your work email, your first SSO sign-in converts it. See Your First SSO Sign-In.

Sign In With SSO

Always start sign-in from the Reagent app. SSO doesn’t work on the reaperagent.com website.
1

Start sign-in in the app

Open Reagent and click Sign in to Reagent. Your browser opens the sign-in page, and the app shows Waiting for browser… with a Cancel button.
2

Enter your work email

Type your work email. After a moment, the password field disappears and a Continue with button shows your company’s name.See a password field or “No account found for this email.” instead? Your account doesn’t use SSO. See Sign In With a Password.
3

Sign in with your company account

Click Continue with, then sign in on your company’s page the way you usually do at work.
4

Return to Reagent

The browser shows Opening Reagent and hands you back to the app. If your browser asks whether to open Reagent, allow it. If nothing happens after a few seconds, click Open Reagent. Then you can close the tab.
5

Finish setup

Once you’re in, the account row at the bottom of Reagent’s sidebar shows Enterprise next to your name. Next:
  1. New to Reagent? Answer a few welcome questions.
  2. Enter your endpoint details in the Custom Endpoint window. You can’t use Reagent until an endpoint works. You enter them once on each computer, and again after you log out. See Custom Endpoint.
  3. Connect Reagent to REAPER, as on any plan. See Quick Start.

Your First SSO Sign-In

Your first SSO sign-in creates your Reagent account. If you already have an account with a password, it converts that account to SSO instead:
  • Your password stops working. From now on, you sign in with SSO.
  • Reagent signs you out on your other computers and removes your endpoint details there, so you enter them again when you next sign in there.
  • Your profile stays the same. Your chats stay too, because they’re stored on your computer.
If your organization is out of seats, your first SSO sign-in stops with a seat-limit message.

Sign In With a Password

The sign-in page asks for your password instead of offering SSO when:
  • You’re exempt. At your organization’s request, Reagent’s team can exempt people such as contractors, or shared and test accounts. SSO isn’t available to you. No password yet? Click Forgot password? on the sign-in page to set one.
  • SSO isn’t switched on for your domain yet, or it’s been switched off. With no account yet, the page says “No account found for this email.” and you can click Sign up.
Either way, you have an Enterprise account once Reagent’s team has registered your organization. See How an Account Becomes Enterprise.
If you sign in to the website with a password (for example, because you’re exempt), don’t buy a plan or credits there. The website still lets you pay, but Reagent can’t use what you buy on an Enterprise account.

Log Out

Click your name at the bottom of Reagent’s sidebar, then click Log out. The Sign out button in the Custom Endpoint window does the same. Logging out:
  • Signs you out of Reagent on all your computers, not only this one.
  • Removes your organization’s endpoint settings, including the API key, from each computer as it’s signed out. You enter them again the next time you sign in there.

Troubleshooting Sign-In

To restart sign-in, go back to Reagent, click Cancel if it’s still waiting, and click Sign in to Reagent again.
You opened the sign-in page on its own, not from the app. Go back to Reagent and click Sign in to Reagent.
If you try to sign up on the website with your work email, it links you to sign in instead. Start sign-in from the Reagent app.
Sign-in failed before your company’s sign-in page opened. Click Continue with again. If it keeps happening, restart sign-in.
Your account doesn’t use SSO right now, for example because you’re exempt or SSO isn’t switched on for your company yet. See Sign In With a Password.
You’re exempt from SSO. Enter your password on the sign-in page.
The message usually names your company. You tried a password, but your account signs in with SSO. Start from the app, type your work email, and click Continue with.
You tried to sign in without SSO, for example with a password or a password reset link, but your organization requires SSO for your account. Start sign-in from the app, type your work email, and click Continue with.
Your account signs in with SSO, so there’s no Reagent password to reset. Start sign-in from the app, type your work email, and click Continue with. If you’re supposed to sign in with a password instead, ask your administrator whether you’re exempt.
On the Opening Reagent page, click Open Reagent. If that doesn’t work, restart sign-in.
Reagent waits up to 10 minutes for you to finish in the browser. If you take longer, restart sign-in.
The browser part of sign-in took too long or was interrupted. Restart sign-in.
The account you used on your company’s sign-in page doesn’t match your organization in Reagent, for example because its email is at a different domain. Sign in with your work account. If you did, contact your IT team.
Every seat your organization has is in use. Ask your administrator for access. They can ask Reagent’s team to change the limit.
Something went wrong while finishing sign-in. Try again from Reagent. If it keeps happening, contact your IT team: the problem may be on your company’s sign-in side.
Reagent finds your existing account by the email address your company’s sign-in sends (capitalization doesn’t matter). If that address is different, for example an alias, Reagent creates a new, separate account instead.
The sign-in page may name your company instead. Your organization’s Enterprise license has ended, so nobody at your domain can sign in, and Reagent signs everyone out. Talk to your administrator. See When Your License Ends.
Reagent signed you out because your sign-in session ended, for example because you logged out on another computer or your account was removed. Click Sign in to Reagent. If you can’t sign in, ask your administrator.

For IT Admins

Before you set up SSO, know how it works with Reagent:
  • WorkOS. Reagent uses WorkOS for SSO. You connect your identity provider through a WorkOS Admin Portal link from Reagent’s team. WorkOS is on Reagent’s subprocessors page.
  • One email domain per organization, such as studio.com. Once SSO is switched on (enforced), anyone who types an email at that domain on the sign-in page goes to your identity provider, unless they’re exempt.
  • SSO is the way in. Once SSO is switched on, Reagent’s sign-in page offers people at your domain who aren’t exempt no password sign-in and no password reset, so they sign in through your identity provider.
  • Email addresses must be at your domain exactly. Reagent reads each person’s email address from your identity provider and refuses other domains, including subdomains, with “This account isn’t set up for single sign-on with your organization.” It matches existing accounts by email address (capitalization doesn’t matter), so a different address, such as an alias, creates a second account instead of converting the existing one, and uses a second seat.
  • Sign-in starts in the Reagent app. IdP-initiated sign-in (from your identity provider’s app dashboard) doesn’t work, and there’s no SSO sign-in to the reaperagent.com website.
  • Reagent’s team manages your organization: the seat limit, exemptions and account removal. People can’t delete their own Enterprise account. There’s no self-serve admin console and no SCIM or directory sync.
  • Access ends with your license, at the exact moment your contract ends. See When Your License Ends.

Set Up SSO

Before you start, have your organization’s AI endpoint ready and tested. When Reagent’s team creates your organization, every existing Reagent account with an email at your domain becomes an Enterprise account, even before SSO is switched on. Those people then need your organization’s endpoint details to keep chatting in Reagent.
Anyone at your domain paying for an individual plan with their work email should cancel it (Manage Subscription in the reaperagent.com dashboard) before your organization is created. After that, the app can’t use the plan or its credits, and once SSO is switched on, they can’t sign in to the website to cancel unless they’re exempt.
1

Contact Reagent's team

Contact Reagent’s team with:
  • your company email domain
  • the organization name people should see on the sign-in page
  • anyone who should keep signing in with a password (see Exemptions)
  • a seat limit, if you want one
Reagent’s team creates your organization and sends you a WorkOS Admin Portal link.
2

Connect your identity provider

Open the WorkOS Admin Portal link and follow the steps. When the portal confirms your connection, you may land on a Reagent page titled Setup complete! You can close it.
3

Tell Reagent's team you're done

They confirm when SSO is switched on for your domain. From then on, people at your domain sign in through your identity provider.
4

Tell your team

Ask people to install the latest version of Reagent (0.15.1 or later) and sign in from the app. Give them your Endpoint URL, API key and Model ID for the Custom Endpoint window.
Plan any change to your SSO connection with Reagent’s team first. If the connection is deactivated or deleted in WorkOS, Reagent is set up to switch SSO off for your domain and alert Reagent’s team.The sign-in page then asks people at your domain for a password. People who sign in with SSO don’t have one, so they can’t sign in the usual way while SSO is off. When the connection is active again, ask Reagent’s team to confirm SSO is back on.

Seats

Your organization has no seat limit unless Reagent’s team sets one. To change it, contact Reagent’s team.
  • A person’s first SSO sign-in uses a seat, whether it creates a new account or converts an existing one. Signing in again never uses another.
  • People who sign in with a password and have never signed in with SSO don’t use a seat.
  • When Reagent’s team removes someone’s account, its seat becomes free again.
  • At the limit, new people see the seat-limit message. People who already have an SSO account keep signing in as normal.

Exemptions

Reagent’s team can exempt people who can’t use your identity provider, such as contractors, or shared and test accounts. Send the list before SSO is switched on, so they can keep signing in from the first day.
  • An exempt person signs in with email and password, and SSO is refused for them. They still have an Enterprise account.
  • If an exempt person has no Reagent account yet, Reagent’s team can create one.
  • Accounts that Reagent’s team creates, and accounts exempted after they switched to SSO, have no password yet. The person clicks Forgot password? on the sign-in page to set one.

Removing Someone’s Access

Reagent has no directory sync, so changes in your identity provider don’t change Reagent accounts. Removing someone in your identity provider also doesn’t sign them out of Reagent on a computer where they’re already signed in. To remove someone’s access, do these in order:
  1. Remove them from Reagent in your identity provider (unassign them from the Reagent app), so they can’t sign in through it again. If you skip this and only ask for the account to be removed, their next SSO sign-in creates a new one and uses a seat.
  2. Revoke their API key. If they have their own API key for your organization’s endpoint, revoke it in your AI gateway. This stops their use of your model right away: until Reagent signs them out, it keeps using the key saved on their computer.
  3. Ask Reagent’s team to remove their Reagent account. Reagent’s team deletes the account permanently, which frees its seat. Any computer where the person is still signed in is signed out within an hour, and Reagent removes your endpoint details from it.

Custom Endpoint

Connect Reagent to your organization’s AI model.

Privacy & Security

Where your conversation goes on an Enterprise account.