About Single Sign-On
Using single sign-on (SSO),
- SAML 2.0andOIDCconfiguration options that support integration with a wide variety of IdPs.
An
enterprise policyto optionally require non-administrative members to log in to Bitwarden with SSO.An
enterprise policyto optionally allow easier auto-fill in non-SSO apps launched from your IdP.Several distinct
member decryption optionsfor safe data access workflows.- Just-In-Time (JIT) provisioningof members via SSO.
tip
Using SSO with Bitwarden retains our zero-knowledge encryption model. Nobody at Bitwarden has access to your data and, similarly, neither should your Identity Provider. That's SSO decouples authentication and decryption. In all implementations, your Identity Provider cannot and will not have access to the decryption key needed to decrypt vault data.
While authentication is handled via your IdP, decryption of your data is controlled by one of several
If you're new to Bitwarden,
Configure your SSO integration using one of the SSO Guides for your chosen IdP. If your IdP isn't listed, you can use the
generic SAMLorgeneric OIDCguide.Test the
member login experienceusing master password decryption.Assess whether a different
member decryption optionswould fit your implementation, and if so begin configuration of that decryption option.Provide information to members, based on the specifics of your implementation, about how to
log in with SSO.