Skip to main content
AhaSend single sign-on lets your team log in through an OpenID Connect identity provider; this guide walks through its setup. Available on Max. See plans and features.
Max plan Feature: OpenID Connect SSO is available exclusively on the Max plan.
Account Owner Access: Only the account owner can configure SSO and bypass it when necessary. Team members must use SSO once enabled.
AhaSend SSO uses OpenID Connect (OIDC); SAML is not supported. Register https://dash.ahasend.com/user/sso/oidc/callback as the redirect URI in your identity provider.

Configuration

Configure SSO in your account settings as the account owner:

Enable SSO

Navigate to SSO settings:
  1. Go to Account Settings in your dashboard
  2. Scroll to OpenID Connect SSO section
  3. Check “Enable OpenID Connect SSO”

Configure Identity Provider

Enter your IdP details:Required Configuration:
  • Configuration Type: PKCE (recommended) or Client Credentials
  • Domain: Comma-separated email domains (e.g., yourcompany.com). You need to show that you own each one; see Verify your SSO domains
  • Issuer URL: Base URL from your IdP (e.g., https://iam.company.com)
  • Client ID: Provided by your identity provider
  • Client Secret: Required for the Client Credentials configuration; not required for PKCE. For PKCE, select S256 as the PKCE method
Optional Settings:
  • Requested Scopes: Space-separated scopes (defaults: openid email profile)
  • Authorization Endpoint: e.g., https://iam.company.com/oauth/v2/authorize
  • Token Endpoint: e.g., https://iam.company.com/oauth/v2/token
  • Userinfo Endpoint: e.g., https://iam.company.com/oauth/v2/userinfo
  • JWKS URI: e.g., https://iam.company.com/oauth/v2/keys

Validate and Activate

Complete SSO setup:
  1. Save your configuration
  2. System validates the settings and checks that you own each new domain
  3. SSO activates if validation is successful

Verify Your SSO Domains

SSO signs in people by their email address, so AhaSend only accepts sign-ins for addresses at your SSO domains, and you need to show that you own each domain when you first add it. Subdomains aren’t included: if your team also uses eu.yourcompany.com, add it as its own domain. A domain counts as verified when either:
  • It is a verified sending domain in the same AhaSend account. If you already send from yourcompany.com, there is nothing more to do. See Domain setup.
  • It has the SSO TXT record. Use this for a domain you don’t send from.
The TXT record is shown under the Domain field in your account settings: The value is the same for every domain in your account, so you can add the record before you save. Replace yourcompany.com with each domain you add. See the DNS provider guides for how to add a record. AhaSend only checks a domain when you first add it. Once it is saved, you can remove the TXT record, and later changes to your DNS won’t stop your team from signing in.
A domain can only be used for SSO by one AhaSend account. If another account already uses your domain, contact support.

How SSO Works

Once OpenID Connect SSO is activated: Team Member Access:
  • Must use SSO: All team members must sign in through your identity provider
  • No regular login: Standard AhaSend login credentials are disabled
  • Access denied: Password reset requests are blocked for team members
Account Owner Access:
  • SSO bypass: Can still use regular AhaSend credentials
  • Password reset: Can request password resets when needed
  • Full control: Can disable SSO if necessary
Team Access: Only users explicitly added as team members can access the account after SSO is enabled.

Supported Identity Providers

Microsoft Entra ID

Azure Active DirectoryPopular enterprise identity provider with comprehensive features

Google Workspace

Google Workspace identity providerIntegrated with Gmail and Google services

Okta

Enterprise SSO PlatformDedicated identity and access management

Self-Hosted Options

Authentik, ZitadelOpen-source identity providers you can host yourself

Troubleshooting

Common setup issues:
  • Enable “Allow public client flows” in app registration
  • Set platform to “Mobile and desktop applications” (not Web or Single-page)
  • Verify redirect URLs match AhaSend’s requirements
Login problems:
  • Verify user is added as team member in AhaSend
  • Check the user’s email address is at one of your SSO domains; sign-ins for other addresses are refused
  • Check your identity provider doesn’t mark the user’s email as unverified (email_verified: false); those sign-ins are refused
  • Confirm user exists in your identity provider
  • Test SSO configuration with account owner first
Saving fails with “We couldn’t verify …”:
  • Add the domain as a sending domain and finish its DNS setup, or add the SSO TXT record
  • Check the record name is _ahasend-sso. followed by the domain, not the domain itself
  • Copy the value exactly from your settings page
  • Wait a few minutes after adding the record; DNS changes can take time to show up
Setup validation fails:
  • Double-check all endpoint URLs are accessible
  • Verify client ID and secret are correct
  • Ensure identity provider is properly configured
  • Test JWKS URI returns valid JSON