Email-first login
Sign-in is email-first: you enter your email and Enfors automatically detects whether your domain is configured for SSO and routes you to the right provider.Providers
Used by the web app and the macOS watcher (browser-based PKCE flow).
Okta (OIDC)
Enterprise OIDC sign-in for organizations standardized on Okta.
Where SSO is used
- Enfors UI — user authentication via SSO domain detection.
- Watcher — SSO during install and
enfors login; tokens are cached to~/.enfors/hooks/tokens.jsonand auto-refreshed. - MCP server — OAuth 2.0 / SSO protects the remote MCP endpoint. See MCP overview.
Configuring a new SSO domain for your organization is an admin operation. Reach out to
the Enfors team to add your domain.