Single sign-on · beta

Single sign-on for your team, included on every plan.

Your team signs in to deploybase with your own Keycloak, Authentik or another OpenID Connect provider. You set it up yourself in a few minutes. No sales call, no add-on, no enterprise tier.

An example of the connection test in deploybase's single sign-on settings, for an Authentik provider at https://auth.example.eu/application/o/acme/. Nine of ten checks pass. One fails: your people cannot be matched to their membership, because Authentik 2025.10 and later report every user's email address as unverified by default. The test says to either trust unverified email addresses on this connection or change the email scope mapping in Authentik.

Set up single sign-on in four steps

Team admins do this themselves under Settings → Single sign-on. You can connect more than one provider to a team.

  1. Register deploybase in your identity provider

    Settings → Single sign-on shows the redirect address before any connection exists, because your provider needs it first. Create an OpenID Connect client there with that address.

  2. Paste the issuer address

    We read your provider's discovery document and show you what we found, the endpoints, the provider type and any setting that will cause trouble, before anything is created.

  3. Add the client id and secret

    That is all you type. Choose whether a first sign-in can create the member for you, and on which role.

  4. Run the test, then sign in from a private window

    The test checks each setting separately and names the one that is wrong. When it passes, sign in once yourself before you share the link.

Access control and offboarding

What connecting a provider changes, and what it deliberately doesn't.

It adds a way in, never takes one away
Connecting a provider does not switch off email and password. A setting typed wrong locks nobody out, and you can fix it while everyone keeps working.
Disabling a connection closes the door
Turn a connection off and nobody signs in through it any more, including members who already linked their account.
Offboarding happens in deploybase
Remove someone from your team and their access ends, even if their account at your identity provider still exists. Every sign-in re-checks membership.
New members are never admins
A first-time sign-in can create the member for you on the role you pick, member or viewer. Admin is not on the list, so a misconfigured provider cannot mint one.
The client secret is write-only
It is stored encrypted and never shown again, not to you and not in the API. Only an owner can delete a connection.

What single sign-on costs on other hosts

Team single sign-on is usually sold as an enterprise extra. Cloudflare is the other host here that includes it on every plan, and it deserves the credit. Our difference: an EU company, OpenID Connect with Keycloak and Authentik as first-class citizens, and a setup that reads the endpoints for you.

QuestiondeploybaseNetlifyVercelRenderCloudflare
Plan you needEvery plan, free includedEnterprisePro with an add-on, or EnterpriseScale or aboveEvery plan
Extra costNonePart of an Enterprise contract$300/month add-on on ProComes with the planNone
ProtocolOpenID ConnectSAMLSAMLSAMLSAML or OpenID Connect
SetupSelf-service: issuer address, client id and secretSelf-service, once on EnterpriseSelf-service, once the add-on is activeSelf-service, once on ScaleSelf-service, endpoints entered by hand
Company based inEUUSUSUSUS

From each provider's own documentation, checked September 2026.

Why it's free

Single sign-on is a security baseline, not a luxury. It is how a team makes sure the person who left last month can no longer deploy to production, and that should not depend on buying a bigger plan. We charge for usage: sites, bandwidth and build minutes. And we don't want deploybase to end up on sso.tax.

What single sign-on doesn't do yet

It is in beta. This is the list we would want to read before choosing it.

  • Okta and Microsoft Entra ID. Not supported yet. Version one is built and tested against Keycloak and Authentik.
  • SAML. Planned, with no date yet. Today a connection is OpenID Connect only.
  • SCIM provisioning. Not built. Members are created at their first sign-in, not pushed from your directory.
  • Requiring single sign-on for every member. Not built. Email and password stay available to everyone, which is also what keeps a wrong setting from locking you out.
  • Colleagues who joined by invitation. They keep signing in with email and password. A connection can only be attached to an account created in your team.

Single sign-on questions

Which identity providers work with deploybase single sign-on?

Keycloak and Authentik, which we test against, and other identity providers that follow the OpenID Connect specification. Okta and Microsoft Entra ID are not supported yet, and SAML is not available. If your provider publishes a discovery document at its issuer address, paste that address and we tell you what we found before anything is created.

Does single sign-on work on the free plan?

Yes. Single sign-on is included on every plan, free included, with no add-on. The size of your team still follows your plan: Free and Starter include 1 team member, Pro (€19/month) and Scale (€49/month) include unlimited members. Connecting a provider does not raise that limit.

Can a wrong setting lock our team out?

No. Connecting a provider adds a way in and never takes one away: email and password keep working for everyone on your team. Run the connection test and sign in once from a private window before you share the sign-in link.

What happens when someone leaves the team?

Remove them from your team in deploybase and their access ends, even if their account at your identity provider still exists, because every sign-in re-checks membership. To stop everyone signing in through a provider at once, disable the connection. That includes members who already linked their account.

Is SAML coming?

SAML is planned, with no date yet, along with Okta and Microsoft Entra ID. If your team needs one of them, email support@deploybase.eu and tell us which. It helps us decide what comes next.

Why is single sign-on free?

Because it is a security baseline, not a luxury. Controlling who can deploy to your sites should not cost more than the sites. We charge for usage: sites, bandwidth and build minutes. We don't want deploybase to end up on sso.tax.

Connect your identity provider today

Create a team on the free plan, open Settings → Single sign-on, and paste your issuer address. The test tells you what is left to do.