Workspace SSO (OIDC + SAML 2.0)
GASecurityReleased Aug 2025Business and Enterprise plansSource: docs.lovable.dev
Workspace SSO (OIDC + SAML 2.0) is Lovable's Security feature: Sign in to Lovable workspaces via Okta, Auth0, Entra ID, and more.
OIDC and SAML 2.0 SSO for workspace access. Supports any compliant IdP, JIT provisioning with configurable default roles, and enforceable session durations (24-48h or 7 days). Service-provider initiated only.
Example workflows
Starting points built from this record, not transcripts of a run. Each prompt is written the way it should be sent, as one paragraph, and each is worth editing before you send it.
Stand it up from scratch
You have read the record and want Workspace SSO (OIDC + SAML 2.0) working in a real project rather than a sandbox.
Set up Workspace SSO (OIDC + SAML 2.0) in this project — sign in to Lovable workspaces via Okta, Auth0, Entra ID, and more. Walk it end to end, tell me exactly what you changed, and flag anything I have to switch on myself before it works.
Expected outcomeA working setup, a plain list of what changed, and a short list of anything left for you to switch on. Check that list before assuming it is done.
Enterprise identity centralization
The record lists this as one of the jobs Workspace SSO (OIDC + SAML 2.0) is meant for, so it is a fair first test of whether it fits your app.
In this project, use Workspace SSO (OIDC + SAML 2.0) for enterprise identity centralization. Build the smallest version that a real user could complete end to end, keep the change scoped to that path, and tell me how to test it myself.
Expected outcomeOne complete path a user can walk, the files and settings that changed, and the steps to test it. Walk it yourself before you ship it.
Review it before you publish
Workspace SSO (OIDC + SAML 2.0) is wired in and you are about to put it in front of people. This is the pass that catches the half-configured version.
Review how this project uses Workspace SSO (OIDC + SAML 2.0) before I publish. Check OIDC and SAML 2.0 and JIT provisioning, list anything that is missing, misconfigured, or only half wired, fix what is safe to fix, and tell me what you left alone and why.
Expected outcomeA findings list split into what was fixed and what was left, with a reason for each. Anything left alone is yours to decide on.
Compliance-mandated auth
A second job the record lists for Workspace SSO (OIDC + SAML 2.0), useful once the first path works.
Extend this project so Workspace SSO (OIDC + SAML 2.0) also covers compliance-mandated auth. Reuse what is already wired rather than adding a parallel setup, and tell me what you reused and what is new.
Expected outcomeA second path built on the same setup, plus a note on what was shared and what was added.
Capabilities
- OIDC and SAML 2.0
- JIT provisioning
- Configurable session durations
- SSO enforcement
Use cases
- Enterprise identity centralization
- Compliance-mandated auth
The link to lovable.dev uses a referral code. The atlas is otherwise unsponsored.
Frequently asked
What is Workspace SSO (OIDC + SAML 2.0)?
Workspace SSO (OIDC + SAML 2.0) is Lovable's Security feature: Sign in to Lovable workspaces via Okta, Auth0, Entra ID, and more. OIDC and SAML 2.0 SSO for workspace access.
Is Workspace SSO (OIDC + SAML 2.0) GA or in beta?
Workspace SSO (OIDC + SAML 2.0) is generally available (GA) on Lovable.
What Lovable plan includes Workspace SSO (OIDC + SAML 2.0)?
Workspace SSO (OIDC + SAML 2.0) is available on Lovable's Business and Enterprise plans plan.
When did Workspace SSO (OIDC + SAML 2.0) launch?
Workspace SSO (OIDC + SAML 2.0) launched on Aug 11, 2025.
Related in Security
See all →What Lovable Shipped
One email a week. Every new feature. Nothing else.
A curated Monday roundup of every Lovable feature added or promoted to GA in the past week — pulled straight from the atlas.
No spam. Unsubscribe anytime. Independent, not affiliated with Lovable AB.