Skip to main content
Organizations on the Enterprise plan can set up Single Sign-On (SSO) so your team signs in to Cartesia through your own identity provider. SSO is self-serve: an organization admin configures, tests, and activates it directly from the Playground, with no back-and-forth with Cartesia. Both SAML and OIDC are supported, including Okta, Microsoft Entra ID, Google Workspace, and custom providers. SSO is powered by our identity provider, Clerk.
SSO is available on the Enterprise plan, and only an organization admin can configure it.

Configure SSO

1

Open your SSO settings

In the Playground, go to your organization’s Privacy settings. Under Single Sign-On (SSO), select Configure SSO, then open the Security tab in the dialog that appears.
2

Add and verify your domains

Add each email domain your team uses to sign in, then verify ownership of each by adding the DNS TXT record shown to your domain’s DNS settings. Verification can take a few minutes to propagate.
3

Connect your identity provider

Select your identity provider and follow the guided steps to connect it over SAML or OIDC. Cartesia shows the service provider details to enter in your provider, and collects your provider’s configuration in return.For provider-specific setup, see Clerk’s enterprise connection guides for Okta, Microsoft Entra ID, and other providers.
4

Test the connection

Use the Test step to run a test sign-in and confirm the connection works end to end before you roll it out to your team.
5

Activate SSO

Select Activate to turn on the connection. Members with an email address on a verified domain then sign in to Cartesia through your identity provider.
Run into any trouble? Reach out to support@cartesia.ai.