> ## Documentation Index
> Fetch the complete documentation index at: https://reaperagent.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On

> Sign in to Reagent with your company account, or set up single sign-on (SSO) for your organization

You don't need a separate Reagent password. Single sign-on is for Enterprise organizations that have set it up with Reagent's team. If you're setting up SSO for your organization, go to [For IT Admins](#for-it-admins).

## For Members

Before you start, you need:

* **The latest version of Reagent** (0.15.1 or later). [Download Reagent](https://www.reaperagent.com/download).
* **Your work email address**, on your company's email domain.
* **Your organization's endpoint details** from your IT team: the **Endpoint URL**, **API key** and **Model ID**. Reagent asks for them after you sign in.

You don't need a Reagent account first. If you already have one with your work email, your first SSO sign-in converts it. See [Your First SSO Sign-In](#your-first-sso-sign-in).

### Sign In With SSO

Always start sign-in from the Reagent app. SSO doesn't work on the reaperagent.com website.

<Steps>
  <Step title="Start sign-in in the app">
    Open Reagent and click **Sign in to Reagent**. Your browser opens the sign-in page, and the app shows **Waiting for browser...** with a **Cancel** button.
  </Step>

  <Step title="Enter your work email">
    Type your work email. After a moment, the password field disappears and a **Continue with** button shows your company's name.

    See a password field or "No account found for this email." instead? Your account doesn't use SSO. See [Sign In With a Password](#sign-in-with-a-password).
  </Step>

  <Step title="Sign in with your company account">
    Click **Continue with**, then sign in on your company's page the way you usually do at work.
  </Step>

  <Step title="Return to Reagent">
    The browser shows **Opening Reagent** and hands you back to the app. If your browser asks whether to open Reagent, allow it. If nothing happens after a few seconds, click **Open Reagent**. Then you can close the tab.
  </Step>

  <Step title="Finish setup">
    Once you're in, the account row at the bottom of Reagent's sidebar shows **Enterprise** next to your name. Next:

    1. **New to Reagent?** Answer a few [welcome questions](/docs/getting-started/quickstart#3-answer-the-welcome-questions).
    2. **Enter your endpoint details** in the **Custom Endpoint** window. You can't use Reagent until an endpoint works. You enter them once on each computer, and again after you [log out](#log-out). See [Custom Endpoint](/docs/enterprise/custom-endpoint).
    3. **Connect Reagent to REAPER**, as on any plan. See [Quick Start](/docs/getting-started/quickstart#4-connect-reagent-to-reaper).
  </Step>
</Steps>

### Your First SSO Sign-In

Your first SSO sign-in creates your Reagent account. If you already have an account with a password, it converts that account to SSO instead:

* Your password stops working. From now on, you sign in with SSO.
* Reagent signs you out on your other computers and removes your endpoint details there, so you enter them again when you next sign in there.
* Your profile stays the same. Your chats stay too, because they're stored on your computer.

If your organization is out of [seats](#seats), your first SSO sign-in stops with a [seat-limit message](#troubleshooting-sign-in).

### Sign In With a Password

The sign-in page asks for your password instead of offering SSO when:

* **You're exempt.** At your organization's request, Reagent's team can [exempt](#exemptions) people such as contractors, or shared and test accounts. SSO isn't available to you. No password yet? Click **Forgot password?** on the sign-in page to set one.
* **SSO isn't switched on** for your domain yet, or it's been switched off. With no account yet, the page says "No account found for this email." and you can click **Sign up**.

Either way, you have an Enterprise account once Reagent's team has registered your organization. See [How an Account Becomes Enterprise](/docs/enterprise/overview#how-an-account-becomes-enterprise).

<Warning>If you sign in to the website with a password (for example, because you're exempt), don't buy a plan or credits there. The website still lets you pay, but Reagent can't use what you buy on an Enterprise account.</Warning>

### Log Out

Click your name at the bottom of Reagent's sidebar, then click **Log out**. The **Sign out** button in the **Custom Endpoint** window does the same. Logging out:

* Signs you out of Reagent on **all** your computers, not only this one.
* Removes your organization's endpoint settings, including the API key, from each computer as it's signed out. You enter them again the next time you sign in there.

### Troubleshooting Sign-In

To *restart sign-in*, go back to Reagent, click **Cancel** if it's still waiting, and click **Sign in to Reagent** again.

<AccordionGroup>
  <Accordion title="“Open the Reagent app to sign in with single sign-on”">
    You opened the sign-in page on its own, not from the app. Go back to Reagent and click **Sign in to Reagent**.
  </Accordion>

  <Accordion title="The website's sign-up page sends you to sign in">
    If you try to sign up on the website with your work email, it links you to sign in instead. Start sign-in from the Reagent app.
  </Accordion>

  <Accordion title="“Could not start SSO sign-in. Please try again.”">
    Sign-in failed before your company's sign-in page opened. Click **Continue with** again. If it keeps happening, restart sign-in.
  </Accordion>

  <Accordion title="The page asks for a password instead of showing Continue with">
    Your account doesn't use SSO right now, for example because you're exempt or SSO isn't switched on for your company yet. See [Sign In With a Password](#sign-in-with-a-password).
  </Accordion>

  <Accordion title="“This account signs in with email and password instead of single sign-on”">
    You're exempt from SSO. Enter your password on the sign-in page.
  </Accordion>

  <Accordion title="“This account uses single sign-on. Please continue with SSO instead.”">
    The message usually names your company. You tried a password, but your account signs in with SSO. Start from the app, type your work email, and click **Continue with**.
  </Accordion>

  <Accordion title="“This account signs in with single sign-on. Open the Reagent app to sign in.”">
    You tried to sign in without SSO, for example with a password or a password reset link, but your organization requires SSO for your account. Start sign-in from the app, type your work email, and click **Continue with**.
  </Accordion>

  <Accordion title="Forgot password says the account has no password to reset">
    Your account signs in with SSO, so there's no Reagent password to reset. Start sign-in from the app, type your work email, and click **Continue with**. If you're supposed to sign in with a password instead, ask your administrator whether you're [exempt](#exemptions).
  </Accordion>

  <Accordion title="The browser doesn't return to Reagent">
    On the **Opening Reagent** page, click **Open Reagent**. If that doesn't work, restart sign-in.
  </Accordion>

  <Accordion title="Sign-in took longer than 10 minutes">
    Reagent waits up to 10 minutes for you to finish in the browser. If you take longer, restart sign-in.
  </Accordion>

  <Accordion title="“Your sign-in session expired before it could complete”">
    The browser part of sign-in took too long or was interrupted. Restart sign-in.
  </Accordion>

  <Accordion title="“This account isn't set up for single sign-on with your organization”">
    The account you used on your company's sign-in page doesn't match your organization in Reagent, for example because its email is at a different domain. Sign in with your work account. If you did, contact your IT team.
  </Accordion>

  <Accordion title="“Your organization has reached its Reagent seat limit”">
    Every seat your organization has is in use. Ask your administrator for access. They can ask Reagent's team to change the limit.
  </Accordion>

  <Accordion title="“Your single sign-on attempt could not be completed”">
    Something went wrong while finishing sign-in. Try again from Reagent. If it keeps happening, contact your IT team: the problem may be on your company's sign-in side.
  </Accordion>

  <Accordion title="Your first SSO sign-in created a new account">
    Reagent finds your existing account by the email address your company's sign-in sends (capitalization doesn't matter). If that address is different, for example an alias, Reagent creates a new, separate account instead.
  </Accordion>

  <Accordion title="“Your organization's Reagent license has ended”">
    The sign-in page may name your company instead. Your organization's Enterprise license has ended, so nobody at your domain can sign in, and Reagent signs everyone out. Talk to your administrator. See [When Your License Ends](/docs/enterprise/overview#when-your-license-ends).
  </Accordion>

  <Accordion title="“Your session ended. Sign in again.”">
    Reagent signed you out because your sign-in session ended, for example because you logged out on another computer or your account was removed. Click **Sign in to Reagent**. If you can't sign in, ask your administrator.
  </Accordion>
</AccordionGroup>

## For IT Admins

Before you set up SSO, know how it works with Reagent:

* **WorkOS.** Reagent uses WorkOS for SSO. You connect your identity provider through a WorkOS Admin Portal link from Reagent's team. WorkOS is on Reagent's [subprocessors page](https://www.reaperagent.com/subprocessors).
* **One email domain per organization**, such as `studio.com`. Once SSO is switched on (enforced), anyone who types an email at that domain on the sign-in page goes to your identity provider, unless they're [exempt](#exemptions).
* **SSO is the way in.** Once SSO is switched on, Reagent's sign-in page offers people at your domain who aren't exempt no password sign-in and no password reset, so they sign in through your identity provider.
* **Email addresses must be at your domain exactly.** Reagent reads each person's email address from your identity provider and refuses other domains, including subdomains, with "This account isn't set up for single sign-on with your organization." It matches existing accounts by email address (capitalization doesn't matter), so a different address, such as an alias, creates a second account instead of converting the existing one, and uses a second seat.
* **Sign-in starts in the Reagent app.** IdP-initiated sign-in (from your identity provider's app dashboard) doesn't work, and there's no SSO sign-in to the reaperagent.com website.
* **Reagent's team manages your organization**: the seat limit, exemptions and account removal. People can't delete their own Enterprise account. There's no self-serve admin console and no SCIM or directory sync.
* **Access ends with your license**, at the exact moment your contract ends. See [When Your License Ends](/docs/enterprise/overview#when-your-license-ends).

### Set Up SSO

Before you start, have your organization's [AI endpoint](/docs/enterprise/custom-endpoint) ready and tested. When Reagent's team creates your organization, every existing Reagent account with an email at your domain becomes an Enterprise account, even before SSO is switched on. Those people then need your organization's endpoint details to keep chatting in Reagent.

<Warning>
  Anyone at your domain paying for an individual plan with their work email should cancel it (**Manage Subscription** in the reaperagent.com dashboard) **before** your organization is created. After that, the app can't use the plan or its credits, and once SSO is switched on, they can't sign in to the website to cancel unless they're exempt.
</Warning>

<Steps>
  <Step title="Contact Reagent's team">
    [Contact Reagent's team](https://www.reaperagent.com/contact) with:

    * your company email domain
    * the organization name people should see on the sign-in page
    * anyone who should keep signing in with a password (see [Exemptions](#exemptions))
    * a seat limit, if you want one

    Reagent's team creates your organization and sends you a WorkOS Admin Portal link.
  </Step>

  <Step title="Connect your identity provider">
    Open the WorkOS Admin Portal link and follow the steps. When the portal confirms your connection, you may land on a Reagent page titled **Setup complete!** You can close it.
  </Step>

  <Step title="Tell Reagent's team you're done">
    They confirm when SSO is switched on for your domain. From then on, people at your domain sign in through your identity provider.
  </Step>

  <Step title="Tell your team">
    Ask people to install the latest version of Reagent (0.15.1 or later) and sign in from the app. Give them your **Endpoint URL**, **API key** and **Model ID** for the [Custom Endpoint](/docs/enterprise/custom-endpoint) window.
  </Step>
</Steps>

<AccordionGroup>
  <Accordion title="Change your SSO connection later">
    Plan any change to your SSO connection with Reagent's team first. If the connection is deactivated or deleted in WorkOS, Reagent is set up to switch SSO off for your domain and alert Reagent's team.

    The sign-in page then asks people at your domain for a password. People who sign in with SSO don't have one, so they can't sign in the usual way while SSO is off. When the connection is active again, ask Reagent's team to confirm SSO is back on.
  </Accordion>
</AccordionGroup>

### Seats

Your organization has no seat limit unless Reagent's team sets one. To change it, contact Reagent's team.

* A person's first SSO sign-in uses a seat, whether it creates a new account or converts an existing one. Signing in again never uses another.
* People who sign in with a password and have never signed in with SSO don't use a seat.
* When Reagent's team removes someone's account, its seat becomes free again.
* At the limit, new people see the [seat-limit message](#troubleshooting-sign-in). People who already have an SSO account keep signing in as normal.

### Exemptions

Reagent's team can exempt people who can't use your identity provider, such as contractors, or shared and test accounts. Send the list before SSO is switched on, so they can keep signing in from the first day.

* An exempt person signs in with email and password, and SSO is refused for them. They still have an Enterprise account.
* If an exempt person has no Reagent account yet, Reagent's team can create one.
* Accounts that Reagent's team creates, and accounts exempted after they switched to SSO, have no password yet. The person clicks **Forgot password?** on the sign-in page to set one.

### Removing Someone's Access

Reagent has no directory sync, so changes in your identity provider don't change Reagent accounts. Removing someone in your identity provider also doesn't sign them out of Reagent on a computer where they're already signed in. To remove someone's access, do these in order:

1. **Remove them from Reagent in your identity provider** (unassign them from the Reagent app), so they can't sign in through it again. If you skip this and only ask for the account to be removed, their next SSO sign-in creates a new one and uses a seat.
2. **Revoke their API key.** If they have their own API key for your organization's endpoint, revoke it in your AI gateway. This stops their use of your model right away: until Reagent signs them out, it keeps using the key saved on their computer.
3. **Ask Reagent's team to remove their Reagent account.** Reagent's team deletes the account permanently, which frees its seat. Any computer where the person is still signed in is signed out within an hour, and Reagent removes your endpoint details from it.

## Related

<CardGroup cols={2}>
  <Card title="Custom Endpoint" icon="plug" href="/docs/enterprise/custom-endpoint">
    Connect Reagent to your organization's AI model.
  </Card>

  <Card title="Privacy & Security" icon="shield" href="/docs/guides/privacy-and-security#enterprise-accounts">
    Where your conversation goes on an Enterprise account.
  </Card>
</CardGroup>
