Skip to main content
Single Sign-On enables your company to authenticate to your Together Organization through your company’s existing Identity Provider (IdP) when configured for SSO. Instead of managing separate credentials, Members sign in with the same account they use for everything else at your company.
SSO is available for Scale and Enterprise accounts. Contact sales to upgrade.

Supported Providers

Together supports SSO via SAML and OIDC protocols with these Identity Providers:
  • Google Workspace
  • Okta
  • Microsoft Entra (Azure AD)
  • JumpCloud
For detailed setup instructions per provider, see the guides below:
ProviderProtocolSetup Guide
Most IdPsSAMLSAML setup guide
Most IdPsOIDCOIDC setup guide
OktaSAMLOkta SAML setup guide
OktaOIDCOkta OIDC setup guide
Google WorkspaceSAMLGoogle Workspace SAML setup guide
Microsoft EntraSAMLMicrosoft Entra SAML setup guide
Microsoft EntraOIDCMicrosoft Entra OIDC setup guide

What SSO Enables

  • Automated provisioning. Members are added to your organization automatically when they authenticate through your IdP.
  • Centralized offboarding. Deactivate a user in your IdP and their Together access is revoked.
  • Shared resources. SSO members can collaborate on fine-tuned models, inference analytics, clusters, and billing within their projects.
  • Audit trail. Individual authentication means you can track who did what.

Setting Up SSO

Contact support or your Account Executive with:
  1. Your company’s legal name
  2. The email domain(s) to associate (e.g., @yourcompany.com)
  3. Which Identity Provider you use
  4. The email address of the initial account owner
Setup typically takes 24 to 48 working hours from when we receive your request. Complex configurations (multiple domains, custom attribute mapping) may take longer.

Migrating from Legacy Enterprise Sign-On

If your team currently uses a shared username/password enterprise account, we recommend migrating to SSO. Shared credential accounts will be deprecated in the coming months. Benefits of migrating:

Session Management

Together manages its own session timeouts independently from your IdP’s default settings. Session duration and re-authentication requirements are configured on the Together side.

FAQs

No. Organizations use either SSO or invitation-based membership, not both. If SSO is enabled, all members authenticate through your IdP.
Existing members will need to re-authenticate through your IdP on their next login. Their resources and project membership are preserved.
Not yet. Self-service SSO configuration is on our roadmap. For now, our team handles setup.

What’s Coming

  • Spend controls per member or project
  • Self-service SSO configuration
  • SCIM provisioning for automated group and role sync

Together's IAM Model

How users, credentials, and resources fit together

Organizations

Manage your org and membership

Roles & Permissions

What Admins and Members can do