
Plans
Configure SSO for a Grok organization
Configure SSO for a Grok organization
Enterprise organizations centralize login at console.x.ai/organization. Organization admins wire Single Sign-On (SSO) to their IdP there. Official guide: Organization Management.
Organizations are Enterprise-only. Contact xAI sales if the /organization page is unavailable.
Configure
- Open console.x.ai/organization as an organization admin.
- Click Configure SSO.
- Pick your IdP from the supported list (Okta, Azure AD, Google Workspace, and others shown in the console).
- Follow the IdP-specific instructions in the console — metadata exchange and attribute mapping are spelled out per provider.
- Save the configuration and run the built-in SSO test.
After activation
SSO is enforced organization-wide once configured.
- Users authenticate through SSO on their next access.
- Choosing Log in with email with a domain-associated address (for example
@yourcompany.com) redirects to your IdP. - Addresses outside the linked domain keep standard login methods.
Tell the org before rollout so people expect the IdP redirect.
Domain association
Link the organization to a company email domain on the same dashboard. Signups and logins from that domain associate with the organization automatically. Admins can list every domain-associated user and their team affiliations under Users, and review linked console teams under Teams.
Pitfalls
- Non-admin accounts cannot open
/organization— ask an organization admin. - Testing only in the console is not enough for rollout; verify a real domain user hits the IdP on next login.
- Outside-domain emails will still use password/social login; that is expected.