# Single Sign-On support

Beta
This feature is in BETA. Please reach out if you would like to use it.

Wallet-as-a-Service now supports Single Sign-On (SSO) using a third party login.

If you are using third party platforms such as Okta, JumpCloud, etc., then using Wallet-as-a-Service SSO support, you can continue to use your login with Wallet-as-a-Service.

**When to use SSO with Wallet-as-a-Service**:

* You are confident in your security posture and SSO configuration
* You want to keep sign-in controls consistent with your organization


**When NOT to use SSO with Wallet-as-a-Service**:

* You want to segregate both authentication and authorization from your organization's single sign-on
* You are not confident your organization's SSO controls are strong enough to also protect your access to Wallet-as-a-Service


Note that once you switch to using SSO with Wallet-as-a-Service, it is your responsibility to secure not only your SSO access but also ensure you have adequate governance controls in place that prevent unauthorized access to Wallet-as-a-Service.

## How to configure SSO

You must have Administrator access (or equivalent) on your authentication platform that you want to configure as SSO, and Administrator role on Wallet-as-a-Service in order to carry out the following steps.

Login to your organization on Wallet-as-a-Service as administrator:

1. Go to [Settings / Security](https://app.development.palisade.co/settings/security)
2. Create a new authentication method


![SSO](./images/single_sign_on_1.png)

1. Follow the wizard to configure with JumpCloud or whatever SSO you are using.


![SSO](./images/sso_2.png)

1. Set the auth method to be default (this is very important, as once a user has been invited it's not possible to change the auth method).


![SSO](./images/sso_3.png)

1. You can invite users as normal using their SSO email addresses.
2. User accepts invite as normal.
3. User can then use "Continue with SSO" to log in via SSO.


![SSO](./images/sso_4.png)