Single sign-on (SSO) lets your team sign in to Testimonial with your company identity provider. It is available on a custom Enterprise plan — not on Free, Starter, Ultimate, or Ultimate+.
There is no self-serve SSO toggle in Settings. We set it up with you after you request it. We use WorkOS to connect your identity provider.
What SSO is
With SSO, teammates sign in through your company’s identity provider (for example Okta, Microsoft Entra ID, or Google Workspace) instead of a separate Testimonial password. After we enable the connection for your company domain, those users are sent to your provider and then back into Testimonial.
Teammates on the connected company domain sign in with SSO after we enable it. Other sign-in methods (password, Google, 2FA) are documented separately: Two-factor authentication and Linking your Gmail account.
Who can get SSO
SSO is listed on the pricing Enterprise card (custom pricing), together with custom usage limits, PO/invoices, and a dedicated success manager.
Ultimate and Ultimate+ are self-serve plans on Settings → Plan. They do not include SSO. Ultimate and Ultimate+ are priced per Space.
Note: If you are on Ultimate+ and need SSO, a custom usage limit, or a PO/invoice, that is an Enterprise conversation — not a plan toggle. See How to upgrade to a higher plan.
How to request SSO
Open testimonial.to and message us in the chat widget.
Say you want SSO. Include your company domain, the identity provider you use, and about how many teammates will sign in.
We confirm Enterprise pricing and collect the WorkOS connection details from your IT admin.
After the connection is active, teammates on that domain sign in with SSO. New SSO users are created as part of the Enterprise setup — there is no Settings screen to turn this on yourself.
Use the chat widget on testimonial.to. Enterprise SSO is set up with you in chat.
What we need from your IT admin
We will ask for the usual identity-provider details so we can create the WorkOS connection, for example:
Your company email domain (the domain teammates will sign in with).
Which identity provider you use.
A technical contact who can finish the SAML or OIDC setup on your side.
You do not create a WorkOS account yourself. We handle that part.
Related
Need help? Message us in the chat widget.
