All help articles
Your workspace

Single sign-on

Let people sign in with your company accounts through SAML: how to connect Google Workspace, Microsoft Entra ID or another provider, test it and turn it on.

Updated September 29, 2026

Without single sign-on, everyone signs in to Capme with a six-digit code sent by email. Single sign-on moves sign-in to your identity provider. It is part of Business and Enterprise, and of the Business trial. The workspace owner sets it up under Access, in the Single sign-on card. Admins can see the card, test the connection and turn single sign-on off.

Capme supports SAML 2.0. You need at least one verified domain first, because the connection only covers addresses at your verified domains. How people join explains how to verify one.

Connecting your provider

  1. Pick where your people sign in: Google Workspace, Microsoft Entra ID or another SAML provider. The next step changes to match.
  2. Create a SAML app in your provider. The card shows the Entity ID and the Reply URL (ACS) to enter there, and walks you through the fields. If someone else looks after your identity provider, send them this step.
  3. Paste what your provider gives you back: a metadata URL, or the metadata file's contents. Use the URL if you have one, because then a new certificate only takes one click to pick up. The URL has to start with https and be reachable from the internet.

Connecting changes nothing for anyone yet. Everybody keeps signing in with the emailed code until you test the connection and turn it on.

Test, then turn it on

Test the connection signs you in through your provider once. When that works, the card says Working and you can switch on Turn on single sign-on. From then on, people at your connected domains can no longer sign in with the emailed code. This applies to your workspace's own people and to anyone at those domains who isn't in a Capme workspace yet. Someone at your domain who belongs to another workspace keeps the code.

There is no password or backup code to fall back on. If your identity provider goes down, an admin who is still signed in can turn single sign-on off on the same card, or you can write to us and we will switch your domains back to the emailed code.

Exceptions

Under People who keep the emailed code, the owner can let one address keep signing in with the code, for 7, 30 or 90 days, with a reason. Any admin can end an exception early.

What happens to existing members

People who are already members keep their account, their recordings and their meetings. The first time they sign in through your provider, Capme moves everything over to that sign-in. People who are already signed in stay signed in.

Someone who isn't a member yet gets into the workspace through single sign-on only if Access is set to Anyone at our domain joins. They then join as a viewer. Otherwise an admin adds them first.

A sign-in through your provider only counts in this workspace. It doesn't open meetings that another company's workspace shared with your people. For those, they sign in with the emailed code, and while single sign-on is on that needs an exception.

If you remove a domain from the workspace, single sign-on stops covering it as well.

Certificates and disconnecting

Your provider signs every sign-in with a certificate that expires. From 30 days before that date, the card shows a warning, and the owner and the admins get an email 30, 14 and 7 days before and once more when it has run out. Sign-in stops working when the certificate runs out, so replace it in your provider in time. With a metadata URL, press Re-read their metadata afterwards. With a pasted file, disconnect and connect again with the new one.

Disconnect stops using your provider for this workspace. Nobody loses their account or anything they recorded.

Still stuck? Write to hello@capme.app.

Single sign-on | Capme