Sign in with single sign-on

Admin · CSM · OM · Finance3 min read

Last verified 2026-09-24

Sign in to ValueRamp using your corporate identity provider (Okta, Entra ID, Google) with your work email or accept an invitation with SSO.

Before you start

  • An active ValueRamp user account or pending workspace invitation
  • Single sign-on enabled by your organization's Admin for your corporate email domain
  • Active credentials with your company's Identity Provider (Okta, Microsoft Entra ID, Google Workspace)

Single sign-on (SSO) allows team members to authenticate into ValueRamp using existing enterprise identity credentials, such as Okta, Microsoft Entra ID, or Google Workspace.

When your organization enables SSO, you can sign in with your company account instead of a ValueRamp password. Your company's Identity Provider (IdP) handles the sign-in, including its password rules and multi-factor authentication (MFA).

Signing In with Single Sign-On

Signing in with single sign-on is initiated from the main ValueRamp login page:

  1. Navigate to the ValueRamp login screen at /login.
  2. Beneath the welcome heading, click the Single sign-on option located alongside Google and Microsoft.
  3. You will be routed to the single sign-on page at /login/sso.
  4. In the Work email field, enter your corporate email address (for example, alex@acme.com).
  5. Click Continue.
  6. ValueRamp matches your email domain against your organization's verified domain list and redirects your browser to your company's IdP login portal.
  7. Enter your corporate credentials and complete any required multi-factor authentication prompt.
  8. Upon successful verification, your IdP returns you directly to your ValueRamp workspace dashboard.

First-Time Users: Accepting an Invitation

Single sign-on verifies the identity of established workspace members. If you are joining a workspace for the first time, you must begin from your email invitation:

  1. Locate the ValueRamp invitation email in your corporate inbox.
  2. Click the invitation link to open the invite acceptance screen at /accept-invite.
  3. Team invitations offer Continue with single sign-on alongside Google and Microsoft. (Customer portal invitations don't — single sign-on is for your team only.)
  4. If your company signs in through an identity provider, click Continue with single sign-on and sign in with your company account.
  5. ValueRamp links your corporate identity to your workspace membership role, landing you directly in the portal without requiring a local password.

Staff Enforcement and Permitted Sign-In Methods

Workspaces can operate in two authentication modes:

  • Optional Single Sign-On: Teammates can sign in using single sign-on or standard email and password.
  • Enforced Single Sign-On: If your Admin turns on Require single sign-on for all staff, password login and third-party buttons (Google, Microsoft) are rejected for all internal team members. Entering your email and password will prompt you to use single sign-on instead.

External customers and client stakeholders collaborating through the customer portal are exempt from internal staff enforcement and continue using their standard login methods.

For details on how Admins configure connections, DNS verification, and enforcement, consult the Set up single sign-on for your team guide.

The ValueRamp login screen with the Single sign-on tile highlighted

1 / 4Click 'Single sign-on' on the login screen

Steps

  1. Click 'Single sign-on' on the login screen

    The ValueRamp login screen with the Single sign-on tile highlighted
  2. Enter your corporate work email address

    The Single sign-on login page with the Work email input field highlighted
  3. Click 'Continue' to route to your identity provider

    The Single sign-on form with entered work email and the Continue button highlighted
  4. Authenticate with your corporate credentials to access your workspace

    The ValueRamp workspace dashboard landing page displaying the Welcome onboarding card

Common questions

Can a new teammate sign in through SSO without an invite?

No. Single sign-on authenticates teammates who are already active members of your workspace. New team members must first accept an email invitation from a workspace Admin by clicking 'Continue with single sign-on'.

What does 'Single sign-on isn't set up for that email domain' mean?

Your email domain isn't part of an enabled single sign-on connection in ValueRamp — for example, the Admin hasn't finished setting it up yet. Sign in with your password instead, or ask your ValueRamp Admin to check Settings → Organisation → Single sign-on.

Can I still sign in with a password or social login if SSO is enabled?

Yes, unless your workspace Admin has enabled mandatory enforcement. When 'Require single sign-on for all staff' is turned on, password and Google or Microsoft sign-in buttons are refused for internal staff.

How do first-time users accept an invitation using single sign-on?

Click the invitation link in your welcome email to open `/accept-invite`. Click 'Continue with single sign-on' to authenticate with your IdP. ValueRamp pairs your corporate identity to your member profile automatically without prompting for a local password.

What should I do if my identity provider session fails or expires?

If your IdP session has timed out, ValueRamp redirects you back to `/login/sso` with an authentication error notice. Re-enter your work email and sign in again with your corporate credentials.

Was this helpful? Tell us what was missing