All updates

Single Sign-On

Let your team sign in to Resend with your identity provider.

Today, we're adding Single Sign-On (SSO) to Resend.

Once it's set up, anyone with an email address on your organization's domain can log in to your Resend team through your identity provider (IdP), no invite required.

SSO is available as an add-on to Scale plans and included with an Enterprise plan.

SSO options

By default, enabling SSO adds a new way for users to log in to your team, although you can enable two additional options:

  • Enforced: users can only sign in through your IdP, and removing a user from the IdP removes them from your Resend team.
  • Restricted: users on your SSO domain cannot create new teams, be invited to, or accept invitations from teams outside your SSO organization. Contact support to enable this for your domain.

Set SSO up

There are a few steps to set up SSO. First, you must be an Admin of your team and use an email address from the domain you want to use for SSO. Follow these steps:

  • Navigate to your Team Settings and click Enable SSO.
  • Enter your organization domain: this is the domain your team members use to log in, it doesn't have to match any domains you have set up to send or receive email.
  • Verify your domain: add a TXT record at the apex of your domain; the unique value will be shown on your dashboard. If it's already verified for sending, this step is skipped.
  • Wait for verification: Resend polls your DNS until it finds the TXT record.
  • Connect your IdP: back in Team Settings click on Finish setup. A new tab opens where you configure the connection to your IdP.

Anyone who signs in through SSO and isn't yet a member of the team is added automatically with the Member role.

Conclusion

SSO gives your team one place to manage who can access Resend, and one place to cut that access off. For the full setup walkthrough and troubleshooting, see the SSO docs.

If you have any questions, please reach out to us and we'll be happy to help.