Skip to main content
Enfors supports enterprise SSO for both the web app and the macOS watcher.

Email-first login

Sign-in is email-first: you enter your email and Enfors automatically detects whether your domain is configured for SSO and routes you to the right provider.

Providers

Google

Used by the web app and the macOS watcher (browser-based PKCE flow).

Okta (OIDC)

Enterprise OIDC sign-in for organizations standardized on Okta.

Where SSO is used

  • Enfors UI — user authentication via SSO domain detection.
  • Watcher — SSO during install and enfors login; tokens are cached to ~/.enfors/hooks/tokens.json and auto-refreshed.
  • MCP server — OAuth 2.0 / SSO protects the remote MCP endpoint. See MCP overview.
Configuring a new SSO domain for your organization is an admin operation. Reach out to the Enfors team to add your domain.