SSO (Single Sign-On) is a feature that enables secure authentication of users in multiple applications and websites with just one set of credentials.
SSO is available for accounts with a minimum of 50 licenses and offers the following benefits:
- It reduces the manual effort for team admins to onboard team members
- It simplifies the login process for team members since they do not have to remember multiple login credentials to access DeepL Pro
Team admins cannot log in with SSO. To configure or adjust SSO settings at any time, admins should continue to log in with their login credentials.
Team members can log in via SSO by signing in via the company’s central identity provider. Everyone who is authenticated by this identity provider can access their respective DeepL account.
Before you start
- SSO is available for accounts with a minimum of 50 licenses and a subscription to one or several of the plans shown at the top of the page.
- Your identity provider must support OpenID Connect v1.0 or SAML v2.0.
- DeepL connects to a single identity provider per account.
- If you are migrating company domains, set SSO up after the migration, not during it.
- Only account admins can rotate the SSO client secret. This cannot be done by by an external IT provider. Learn more about admins and teal roles in this article.
Setting up SSO in four steps
-
Choose a domain name: allowed characters are letters, numbers, and hyphens, starting
with a letter. No periods are allowed. - Request approval: go to your Settings tab, and under Team click Set up SSO
- Configure the protocol in OpenID Connect or SAML.
- Choose provisioning: JIT is on by default. Use SCIM if you want DeepL to mirror your directory.
FInd a more detailed guide on setting up SSO for your account in this article.
Supported platforms
- Web translator
- Desktop apps
- Mobile apps
- Browser extensions
- DeepL for Microsoft Word
- DeepL for Microsoft Outlook
If you have a DeepL Pro team plan and wish to make use of the SSO login, find more details here.
User provisioning
We support the following types of user provisioning with SSO:
- JIT (Just-In-Time) provisioning: enabled by default when SSO is enabled for your team. For more information, see this article.
- SCIM (System for Cross-domain Identity Management): additional feature that needs additional set up and works in combination with SSO. For more information, see this article.