For the complete documentation index, see llms.txt. This page is also available as Markdown.

SSO

Single sign-on (SSO)

Tally supports SSO so your team can sign in with your existing identity provider — no separate Tally password required.

Once SSO is active, users enter their work email on the login page and are redirected to your IdP (Microsoft Entra ID, Okta, Google Workspace, and others). Password login is disabled for your organization once SSO is configured.

Setting up SSO

SSO setup is self-serve. A Tally admin can configure it directly from the product:

  1. Sign in to Tally as an admin

  2. Go to Settings → Company → Authentication (/settings/company/authentication)

  3. Click Configure SSO

  4. Open the SSO Configuration Portal link (valid for 5 minutes)

  5. In the portal, connect your identity provider and complete the SAML setup

  6. Assign the users or groups who should have access

When setup is complete, the Authentication page shows SSO is configured. Users with access through your IdP can sign in immediately.

Note: You need to be logged into Tally to generate the portal link. If your IT team doesn't have a Tally account yet, invite them from Settings → Company → Users first, or have an existing admin generate the link and share it.

What users see at login

After SSO is live, the login flow is automatic:

  1. User enters their work email address

  2. Tally detects SSO for their organization

  3. User is redirected to your identity provider to sign in

  4. After successful authentication, they land in Tally

No password field is shown for SSO-enabled organizations.

Last updated

Was this helpful?