Two-factor authentication & SSO

Protect every account with passkeys or TOTP and connect your identity provider via SAML or OIDC.

Guide1 min readUpdated 22 Sept 2026.md
On this page

Two-factor authentication#

Go to Account → Security and add a passkey (WebAuthn) or an authenticator app (TOTP). Save the ten recovery codes somewhere safe.

Project owners can make 2FA mandatory for all members under Project → Settings → Security.

Single sign-on#

SAML 2.0 and OpenID Connect are supported — Okta, Microsoft Entra ID, Google Workspace, Keycloak and others. Use these values in your identity provider:

Text
Entity ID:          https://console.avenlith.com/saml/metadata
ACS URL:            https://console.avenlith.com/saml/acs
Name ID format:     emailAddress
Attributes:         email, firstName, lastName, groups

Groups from the identity provider can be mapped to Avenlith roles, so access is removed automatically when someone leaves the company.

Was this page helpful?

Still need help?

Our engineers answer tickets 24/7 — average first response in 7 minutes.

Contact support