Skip to main content

About SSO

Agentic Document Extraction supports SSO via SAML 2.0 and OpenID Connect (OIDC), letting your organization manage Agentic Document Extraction access through your existing identity provider (IdP). Common IdPs include Okta, Microsoft Entra ID (formerly Azure AD), OneLogin, Ping Identity, and Google Workspace.
Users can also sign in with Google or GitHub without any additional setup. This page covers SSO setup via SAML 2.0 and OIDC only.

Availability

SSO via SAML 2.0 and OIDC is available on the Enterprise plan.

What to Know Before Enabling SSO

SSO Replaces Existing Login Methods

Once SSO is enabled for your organization, it becomes the only way users can log in to Agentic Document Extraction. Users will no longer be able to sign in with a password, Google, or GitHub. This is by design; it ensures that all user access is managed through your IdP, so your organization’s security policies are consistently enforced. To avoid disruption, communicate this change to all Agentic Document Extraction users in your organization before enabling SSO.

User Access and JIT Provisioning

Your IT department controls who can access Agentic Document Extraction through your IdP by managing user groups. Having a company email address does not automatically grant access. Users must be included in the group configured for Agentic Document Extraction in your IdP. When setting up SSO, let the LandingAI team know which option you prefer for adding users to your Agentic Document Extraction organization:
  • By invitation: Only users who have been invited to your Agentic Document Extraction organization can log in, even after SSO is enabled. For information about manually inviting users, see Organizations & Members.
  • Just-in-Time (JIT) provisioning: Any user in your IdP’s user group who successfully authenticates via SSO is automatically added to your Agentic Document Extraction organization the first time they log in, with no invitation required.

Enable SSO

SSO setup involves multiple steps and ongoing coordination between your team and the LandingAI team. Here is an overview of the process:
  1. Request SSO through your Organization Settings.
  2. The LandingAI team reaches out to begin the process.
  3. Share the required information with the LandingAI team: SAML 2.0 or OIDC.
  4. The LandingAI team enters your information in the Agentic Document Extraction backend.
  5. The LandingAI team shares configuration details with you. Add these to your IdP.
  6. Test that SSO is working correctly.

Request SSO

To request SSO:
  1. Log in to https://ade.landing.ai/.
  2. Go to the Organization Settings page (to navigate there manually, click your profile icon at the bottom left corner of the page and click Organization Settings).
  3. In the Single Sign-On (SSO) box, click Contact Support. This sends an automated message to the LandingAI team. The team will contact you about next steps for setting up SSO.

Required Information for SAML 2.0

Share the following information with the LandingAI team. Most of it can be found in your IdP’s SAML configuration page. The examples below are for Microsoft Entra ID. Formats and field names vary by IdP.

Required Information for OIDC

Share the following information with the LandingAI team. Most of it can be found in your IdP’s OIDC configuration page. The examples below are for Microsoft Entra ID. Formats and field names vary by IdP.

Complete Setup in Your IdP

After the LandingAI team enters your information in the Agentic Document Extraction backend, they will continue coordinating with you to complete the setup. The LandingAI team will give you the following information to enter in your IdP configuration page:

Test That SSO Is Working Correctly

After adding the information from the LandingAI team, test that SSO is working correctly:
  1. Go to https://login.landing.ai/sign-in.
  2. If you are currently logged in, log out.
  3. Click Continue with Enterprise SSO and follow the on-screen prompts to log in. If you’re unable to log in, send an email to support@landing.ai.

View Your SSO Settings

After SSO has successfully been configured, you can view your SSO settings in read-only mode in Agentic Document Extraction:
  1. Log in to https://ade.landing.ai/.
  2. Go to the Organization Settings page (to navigate there manually, click your profile icon at the bottom left corner of the page and click Organization Settings).
  3. In the Single Sign-On (SSO) box, click View Details. The SSO settings display.