One login for the whole team — the one your company already manages

Connect Okta, Microsoft Entra ID, or Google Workspace over OpenID Connect. Members type their work email on the sign-in page, authenticate with your identity provider, and land in InterMIND on your team — no separate passwords to create, rotate, or forget.

SSO sign-in Work email entered
InterMIND sign-in
maria@acme.com verified domain
Sign in with SSO
Your identity provider
OktaMicrosoft Entra IDGoogle Workspace
Team audit log

The email's domain decides everything: only domains your team verified via DNS are accepted, and every SSO sign-in lands in the exportable team audit log.

How it works

  1. 1

    Verify your domain

    Prove you own yourcompany.com with a DNS TXT record. SSO sign-in only accepts emails on domains your team has verified — that is the tenant boundary.

  2. 2

    Connect your identity provider

    Register an OIDC web application in Okta or Microsoft Entra ID and paste the issuer URL and client credentials into the SSO card. Google Workspace connects without any app registration.

  3. 3

    Members sign in with SSO

    On the sign-in page they choose Sign in with SSO, enter their work email, and authenticate with your IdP. Anyone on a verified domain joins your team automatically — no invites to send.

  4. 4

    Every sign-in is on the record

    Each SSO login is written to the team audit log, exportable from the Users page. Plan, domain, and configuration checks run server-side on both the sign-in start and the callback.

Set it up from the Integrations page

The setup guide walks through the exact fields for Okta, Microsoft Entra ID, and Google Workspace, the redirect URI to register, and what each troubleshooting message means.

Questions worth asking