Account Owner Access: Only the account owner can configure SSO and bypass it when necessary. Team members must use SSO once enabled.
https://dash.ahasend.com/user/sso/oidc/callback as the redirect URI in your identity provider.
Configuration
Configure SSO in your account settings as the account owner:Enable SSO
Navigate to SSO settings:
- Go to Account Settings in your dashboard
- Scroll to OpenID Connect SSO section
- Check “Enable OpenID Connect SSO”
Configure Identity Provider
Enter your IdP details:Required Configuration:
- Configuration Type: PKCE (recommended) or Client Credentials
- Domain: Comma-separated email domains (e.g.,
yourcompany.com). You need to show that you own each one; see Verify your SSO domains - Issuer URL: Base URL from your IdP (e.g.,
https://iam.company.com) - Client ID: Provided by your identity provider
- Client Secret: Required for the Client Credentials configuration; not required for PKCE. For PKCE, select
S256as the PKCE method
- Requested Scopes: Space-separated scopes (defaults:
openid email profile) - Authorization Endpoint: e.g.,
https://iam.company.com/oauth/v2/authorize - Token Endpoint: e.g.,
https://iam.company.com/oauth/v2/token - Userinfo Endpoint: e.g.,
https://iam.company.com/oauth/v2/userinfo - JWKS URI: e.g.,
https://iam.company.com/oauth/v2/keys
Validate and Activate
Complete SSO setup:
- Save your configuration
- System validates the settings and checks that you own each new domain
- SSO activates if validation is successful
Verify Your SSO Domains
SSO signs in people by their email address, so AhaSend only accepts sign-ins for addresses at your SSO domains, and you need to show that you own each domain when you first add it. Subdomains aren’t included: if your team also useseu.yourcompany.com, add it as its own domain. A domain counts as verified when either:
- It is a verified sending domain in the same AhaSend account. If you already send from
yourcompany.com, there is nothing more to do. See Domain setup. - It has the SSO TXT record. Use this for a domain you don’t send from.
The value is the same for every domain in your account, so you can add the record before you save. Replace
yourcompany.com with each domain you add. See the DNS provider guides for how to add a record.
AhaSend only checks a domain when you first add it. Once it is saved, you can remove the TXT record, and later changes to your DNS won’t stop your team from signing in.
A domain can only be used for SSO by one AhaSend account. If another account already uses your domain, contact support.
How SSO Works
Once OpenID Connect SSO is activated: Team Member Access:- Must use SSO: All team members must sign in through your identity provider
- No regular login: Standard AhaSend login credentials are disabled
- Access denied: Password reset requests are blocked for team members
- SSO bypass: Can still use regular AhaSend credentials
- Password reset: Can request password resets when needed
- Full control: Can disable SSO if necessary
Supported Identity Providers
Microsoft Entra ID
Azure Active DirectoryPopular enterprise identity provider with comprehensive features
Google Workspace
Google Workspace identity providerIntegrated with Gmail and Google services
Okta
Enterprise SSO PlatformDedicated identity and access management
Self-Hosted Options
Authentik, ZitadelOpen-source identity providers you can host yourself
Troubleshooting
Microsoft Entra ID Configuration
Microsoft Entra ID Configuration
Common setup issues:
- Enable “Allow public client flows” in app registration
- Set platform to “Mobile and desktop applications” (not Web or Single-page)
- Verify redirect URLs match AhaSend’s requirements
Team Member Access Issues
Team Member Access Issues
Login problems:
- Verify user is added as team member in AhaSend
- Check the user’s email address is at one of your SSO domains; sign-ins for other addresses are refused
- Check your identity provider doesn’t mark the user’s email as unverified (
email_verified: false); those sign-ins are refused - Confirm user exists in your identity provider
- Test SSO configuration with account owner first
We Couldn't Verify a Domain
We Couldn't Verify a Domain
Saving fails with “We couldn’t verify …”:
- Add the domain as a sending domain and finish its DNS setup, or add the SSO TXT record
- Check the record name is
_ahasend-sso.followed by the domain, not the domain itself - Copy the value exactly from your settings page
- Wait a few minutes after adding the record; DNS changes can take time to show up
Configuration Validation Errors
Configuration Validation Errors
Setup validation fails:
- Double-check all endpoint URLs are accessible
- Verify client ID and secret are correct
- Ensure identity provider is properly configured
- Test JWKS URI returns valid JSON

