Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Identity features

These identity features answer different questions and have separate eligibility:
  • SAML controls who signs in. Add it when users on a verified company domain should authenticate through your identity provider. It does not create users.
  • SCIM controls who exists. Add it when your identity provider should create, update, and deactivate workspace users — especially for reliable offboarding.
  • Custom access domain controls where clients connect. Add it when the portal and MCP endpoint should be served from a hostname your organization controls.
FeaturePurposePlanWho can configure
Managed SAMLSign users in through the identity provider for a verified company domainBusinessWorkspace owner
SCIMProvision and deactivate workspace users from your identity provider (Microsoft Entra ID or Okta)BusinessWorkspace owner
Custom access domainServe the workspace portal and MCP endpoint from a company-controlled hostnameReserved for a future MSP packageWorkspace owner
Every active managed customer workspace includes that customer's isolated SAML and SCIM configuration. Custom access domains are not included automatically. Configure identity from the customer context; do not reuse the managing company's identity metadata or SCIM token. See Customer identity and cloud access.