Google SSO Enforcement
This section explains how to enforce Google OAuth/SSO authentication for users in theyour-company.com email domain.
Create SSO Enforcement Rule
- Navigate to Organization Settings → Single Sign-On.
- Select Add SSO Enforcement Rule.
- In Email Domain, enter:
your-company.com - Create rule
Expected Behavior
Once enabled, all users with an email address ending in@your-company.com will be required to sign in using Google SSO.
Users will no longer be able to authenticate with password-based login methods for this domain.
Okta Configuration
Cantina integrates directly with Okta for authentication. The setup process involves configuring an application in Okta’s admin console and then connecting it through Cantina’s SSO settings.Okta Settings
- Navigate to the Okta Admin Console and select Applications.
- Click Create App Integration and select OIDC - OpenID Connect, then click Next.
- Select Web Application as the application type.
- Configure your application:
- Name your application (e.g., “Cantina”)
- Set the Sign-in redirect URI to:
https://cantina-prod.us.auth0.com/login/callback
Cantina Settings
- Go to your organization’s SSO settings at https://cantina.xyz/organization/settings/sso
- Click Add SSO Connection
- Enter the following information from your Okta application:
All users with this email domain will be automatically redirected to Okta when they log in to Cantina.