> For the complete documentation index, see [llms.txt](https://docs.kernel.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.kernel.ai/security/sso-saml.md).

# SSO/SAML

## What is SSO (and SAML)?

* SSO: One secure login to access all your tools.
* SAML: An industry-standard protocol that lets your Identity Provider (IdP) (e.g., Okta, Microsoft Entra ID/Azure AD, Google Workspace, OneLogin, Ping) authenticate users for Kernel without new passwords.

## Why it matters

SSO lets your team manage Kernel access from your existing IdP. You can enforce MFA, conditional access, group-based access, offboarding, and audit logging in one place, while Kernel avoids storing user passwords.

## FAQ

Will this work with our IdP?

* Yes - Kernel can support Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, Ping, and other SAML 2.0 providers.

Does Kernel support password authentication?

* No. Kernel currently supports email OTP and SSO. SAML can be enabled if your organization requires it.

What does Kernel use for the SSO/SAML?

* Kernel uses WorkOS for SSO/SAML connection management.
