Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Identity and access

Business workspaces can add managed SAML, SCIM provisioning, and a custom access domain. Only a workspace owner can configure these features.
FeaturePurpose
Managed SAMLSign users in through the identity provider for a verified company domain
SCIMProvision and deactivate workspace users from Microsoft Entra
Custom access domainServe the workspace portal and MCP endpoint from a company-controlled hostname
These features solve different jobs. A custom hostname does not configure sign-in, and SAML does not provision or remove users.
For a managed customer, the customer identity package supplies that customer's separate identity configuration and custom access domain. Configure it from the customer context; do not reuse the MSP's identity metadata or SCIM token.

Change control

Before changing identity:
  1. Confirm the selected workspace and verified domain.
  2. Preserve an existing administrator access path.
  3. Schedule provider-side changes and Stackyapper changes together.
  4. Test with a non-owner user before broad rollout.
  5. Review the resulting identity change in Audit.
Never send SAML metadata containing secrets, SCIM bearer tokens, or session data to support.