--- title: "SSO Overview" sidebarTitle: "Overview" description: "Learn how to log in to Infisical via SSO protocols." --- Infisical offers Google SSO and GitHub SSO for free across both Infisical Cloud and Infisical Self-hosted. Infisical also offers SAML SSO authentication and OpenID Connect (OIDC) but as paid features that can be unlocked on Infisical Cloud's **Pro** tier or via enterprise license on self-hosted instances of Infisical. On this front, we support industry-leading providers including Okta, Azure AD, and JumpCloud; with any questions, please reach out to team@infisical.com. You can configure your organization in Infisical to have members authenticate with the platform via protocols like [SAML 2.0](https://en.wikipedia.org/wiki/SAML_2.0) or [OpenID Connect](https://openid.net/specs/openid-connect-core-1_0.html). ## Identity providers Infisical supports these and many other identity providers: - [Google SSO](/documentation/platform/sso/google) - [GitHub SSO](/documentation/platform/sso/github) - [GitLab SSO](/documentation/platform/sso/gitlab) - [Okta SAML](/documentation/platform/sso/okta) - [Azure SAML](/documentation/platform/sso/azure) - [JumpCloud SAML](/documentation/platform/sso/jumpcloud) - [Keycloak SAML](/documentation/platform/sso/keycloak-saml) - [Google SAML](/documentation/platform/sso/google-saml) - [Auth0 SAML](/documentation/platform/sso/auth0-saml) - [Keycloak OIDC](/documentation/platform/sso/keycloak-oidc) - [Auth0 OIDC](/documentation/platform/sso/auth0-oidc) - [General OIDC](/documentation/platform/sso/general-oidc) If your required identity provider is not shown in the list above, please reach out to [team@infisical.com](mailto:team@infisical.com) for assistance. ## FAQ By default, Infisical Cloud is configured to not trust emails from external identity providers to prevent any malicious account takeover attempts via email spoofing. Accordingly, Infisical creates a new user for anyone provisioned through an external identity provider and requires an additional email verification step upon their first login. If you're running a self-hosted instance of Infisical and would like it to trust emails from external identity providers, you can configure this behavior in the Server Admin Console.