Single sign-on · beta
Single sign-on for your team, included on every plan.
Your team signs in to deploybase with your own Keycloak, Authentik or another OpenID Connect provider. You set it up yourself in a few minutes. No sales call, no add-on, no enterprise tier.
Set up single sign-on in four steps
Team admins do this themselves under Settings → Single sign-on. You can connect more than one provider to a team.
-
Register deploybase in your identity provider
Settings → Single sign-on shows the redirect address before any connection exists, because your provider needs it first. Create an OpenID Connect client there with that address.
-
Paste the issuer address
We read your provider's discovery document and show you what we found, the endpoints, the provider type and any setting that will cause trouble, before anything is created.
-
Add the client id and secret
That is all you type. Choose whether a first sign-in can create the member for you, and on which role.
-
Run the test, then sign in from a private window
The test checks each setting separately and names the one that is wrong. When it passes, sign in once yourself before you share the link.
Your members then sign in at app.deploybase.eu/login/sso/your-team with the account they already use at work.
Access control and offboarding
What connecting a provider changes, and what it deliberately doesn't.
- It adds a way in, never takes one away
- Connecting a provider does not switch off email and password. A setting typed wrong locks nobody out, and you can fix it while everyone keeps working.
- Disabling a connection closes the door
- Turn a connection off and nobody signs in through it any more, including members who already linked their account.
- Offboarding happens in deploybase
- Remove someone from your team and their access ends, even if their account at your identity provider still exists. Every sign-in re-checks membership.
- New members are never admins
- A first-time sign-in can create the member for you on the role you pick, member or viewer. Admin is not on the list, so a misconfigured provider cannot mint one.
- The client secret is write-only
- It is stored encrypted and never shown again, not to you and not in the API. Only an owner can delete a connection.
What single sign-on costs on other hosts
Team single sign-on is usually sold as an enterprise extra. Cloudflare is the other host here that includes it on every plan, and it deserves the credit. Our difference: an EU company, OpenID Connect with Keycloak and Authentik as first-class citizens, and a setup that reads the endpoints for you.
| Question | deploybase | Netlify | Vercel | Render | Cloudflare |
|---|---|---|---|---|---|
| Plan you need | Every plan, free included | Enterprise | Pro with an add-on, or Enterprise | Scale or above | Every plan |
| Extra cost | None | Part of an Enterprise contract | $300/month add-on on Pro | Comes with the plan | None |
| Protocol | OpenID Connect | SAML | SAML | SAML | SAML or OpenID Connect |
| Setup | Self-service: issuer address, client id and secret | Self-service, once on Enterprise | Self-service, once the add-on is active | Self-service, once on Scale | Self-service, endpoints entered by hand |
| Company based in | EU | US | US | US | US |
From each provider's own documentation, checked September 2026.
Why it's free
Single sign-on is a security baseline, not a luxury. It is how a team makes sure the person who left last month can no longer deploy to production, and that should not depend on buying a bigger plan. We charge for usage: sites, bandwidth and build minutes. And we don't want deploybase to end up on sso.tax.
What single sign-on doesn't do yet
It is in beta. This is the list we would want to read before choosing it.
- Okta and Microsoft Entra ID. Not supported yet. Version one is built and tested against Keycloak and Authentik.
- SAML. Planned, with no date yet. Today a connection is OpenID Connect only.
- SCIM provisioning. Not built. Members are created at their first sign-in, not pushed from your directory.
- Requiring single sign-on for every member. Not built. Email and password stay available to everyone, which is also what keeps a wrong setting from locking you out.
- Colleagues who joined by invitation. They keep signing in with email and password. A connection can only be attached to an account created in your team.
Single sign-on questions
Which identity providers work with deploybase single sign-on?
Keycloak and Authentik, which we test against, and other identity providers that follow the OpenID Connect specification. Okta and Microsoft Entra ID are not supported yet, and SAML is not available. If your provider publishes a discovery document at its issuer address, paste that address and we tell you what we found before anything is created.
Does single sign-on work on the free plan?
Yes. Single sign-on is included on every plan, free included, with no add-on. The size of your team still follows your plan: Free and Starter include 1 team member, Pro (€19/month) and Scale (€49/month) include unlimited members. Connecting a provider does not raise that limit.
Can a wrong setting lock our team out?
No. Connecting a provider adds a way in and never takes one away: email and password keep working for everyone on your team. Run the connection test and sign in once from a private window before you share the sign-in link.
What happens when someone leaves the team?
Remove them from your team in deploybase and their access ends, even if their account at your identity provider still exists, because every sign-in re-checks membership. To stop everyone signing in through a provider at once, disable the connection. That includes members who already linked their account.
Is SAML coming?
SAML is planned, with no date yet, along with Okta and Microsoft Entra ID. If your team needs one of them, email support@deploybase.eu and tell us which. It helps us decide what comes next.
Why is single sign-on free?
Because it is a security baseline, not a luxury. Controlling who can deploy to your sites should not cost more than the sites. We charge for usage: sites, bandwidth and build minutes. We don't want deploybase to end up on sso.tax.
Connect your identity provider today
Create a team on the free plan, open Settings → Single sign-on, and paste your issuer address. The test tells you what is left to do.