Hourzero

Single sign-on (SSO)

Let employees sign in to Hourzero with their company account, using one OIDC or SAML connection on an Enterprise plan.

Single sign-on (SSO) lets your employees sign in to Hourzero with the same company account they use for email and other work tools. Your IT team controls who can get in, and people have one less password to remember.

You only need this page if your company uses an identity provider, such as Okta, Microsoft Entra ID, or Google Workspace, and you're on an Enterprise plan. If that's not you, your team can sign in with email and password or Google. Setting up SSO is usually a job for your IT administrator.

Where to find it: open Workspace Settings → Single sign-on.

How it works

You connect Hourzero to your identity provider once, then prove you own your company's email domain. After that, anyone with an email address on that domain can sign in through your company's sign-in page and join the workspace.

  1. 1ConnectAdd your identity provider's details in Hourzero.
  2. 2Verify domainAdd a DNS record that proves you own acme.com.
  3. 3TestSign in through SSO yourself to check it works.
  4. 4ShareEmployees choose Sign in with SSO and use their work email.

Before you begin

Check that you have all of these:

  • An Enterprise team workspace. SSO isn't available on Free, Hobby, Standard, or Pro, or in a personal workspace. On other plans, the page shows Enterprise SSO with a View plans button.
  • The Owner or Admin role in that workspace. Members see Administrator access required.
  • Admin access to your identity provider, so you can create an app there.
  • Access to your company's DNS settings (where your domain's records are managed), or someone who can add a record for you.
  • One company email domain, such as acme.com. Each workspace has one SSO connection, and each domain can belong to only one connection.

Note

The domain must match exactly. A connection for acme.com accepts maya@acme.com but not maya@eu.acme.com.

Choose a protocol

Hourzero supports two standard ways of connecting. Pick the one your identity provider recommends, or the one your IT team already uses for other apps.

  • OpenID Connect (OIDC) is the newer, simpler option. You copy a few values back and forth.
  • SAML 2.0 is the older standard, common in large companies. You exchange a metadata file.

You can't switch protocols on a saved connection. To change it later, remove the connection and create a new one.

Set up an OIDC connection

  1. Open Workspace Settings → Single sign-on and select Set up SSO.
  2. Enter a Connection name your team will recognise, such as Acme Okta.
  3. Enter your Company domain, such as acme.com. Don't include https:// or an @.
  4. Under Protocol, choose OpenID Connect (OIDC).
  5. Copy the Redirect URI that Hourzero shows.
  6. In your identity provider, create a new web application that uses OIDC. Paste the Redirect URI as its sign-in redirect (or callback) address.
  7. Back in Hourzero, enter the app's Issuer URL, Client ID, and Client secret from your identity provider. The Issuer URL must start with https://.
  8. Select Save connection. You see SSO connection saved. Verify your domain to enable sign-in.

Hourzero asks your identity provider for each person's email address and name (the openid, email, and profile scopes). It always uses PKCE, an extra security check during sign-in, so leave PKCE allowed in your provider's app settings.

Set up a SAML connection

  1. Open Workspace Settings → Single sign-on and select Set up SSO.
  2. Enter a Connection name and your Company domain.
  3. Under Protocol, choose SAML 2.0.
  4. Copy the Entity ID / audience and ACS URL values that Hourzero shows.
  5. In your identity provider, create a new SAML app. Paste the Entity ID as its audience (SP entity ID) and the ACS URL as its single sign-on (reply) URL.
  6. Set the app to sign its assertions. Hourzero rejects unsigned assertions and older signing methods.
  7. Back in Hourzero, enter the Identity provider SSO URL from your provider.
  8. Paste your provider's metadata into Identity provider metadata XML. It must include the signing certificate and the single sign-on address.
  9. Check Email attribute (default email) and Name attribute (default displayName). Change them to match the attribute names your provider sends.
  10. Select Save connection.

After saving, you can open View service provider metadata if your identity provider prefers to import Hourzero's details from a file.

Important

Employees must start sign-in from Hourzero. Starting from an app tile on your identity provider's dashboard doesn't work.

Verify your company domain

Verifying the domain proves your company owns it. SSO sign-in stays off until this step is done, and the connection shows Verification required.

  1. On the saved connection, select Get verification token. Hourzero shows a TXT record host and a TXT record value.
  2. In your DNS settings for acme.com, add a new TXT record. Copy the host and value exactly as shown.
  3. Wait for the record to go live. This can take from a few minutes to a few hours, depending on your DNS provider.
  4. Select Verify domain. You see Domain verified. SSO sign-in is ready. and the badge changes to Verified.

Tip

If verification fails with "Unable to verify domain ownership", the record isn't visible yet or doesn't match. Check for extra spaces or a missing underscore at the start of the host. If your DNS provider adds your domain to the host automatically, don't type acme.com on the end yourself. Wait a little longer, then try again.

The verification token is valid for one week. If it expires, select Get verification token again for a new one, and update the DNS record.

Test sign-in

  1. On the verified connection, select Test sign-in. The Sign in with SSO page opens.
  2. Enter your Work email and select Continue with SSO.
  3. Sign in on your company's sign-in page.
  4. Hourzero brings you back to the Single sign-on settings page.

Always test before you tell your team. A saved connection and a verified domain don't prove that the identity provider sends the right details.

Tell employees how to sign in

Share one of these with your team:

  • The sign-in page: go to the Hourzero sign-in page, select Sign in with SSO, enter their Work email, and select Continue with SSO.
  • The direct link: copy the SSO sign-in link from the connection and share it. It opens the Sign in with SSO page already tied to your company's connection.

After signing in, employees land in your company workspace.

What happens the first time someone signs in

  • People who aren't in the workspace yet join it as a Member. If they don't have a Hourzero account, one is created for them.
  • People already in the workspace keep their current role, including owners and admins.
  • Someone with a pending invitation needs to accept that invitation to join. The invitation decides their role.
  • People who already have a Hourzero account with the same work email sign in to that same account, so they keep their profile and other workspaces.

To give someone more access, change their role in Members and invitations.

Note

SSO is an extra way to sign in. It doesn't turn off email and password or Google sign-in for your team.

Edit a connection

  1. Select Edit connection.
  2. Change the details you need. Leave Client secret or Identity provider metadata XML blank to keep what's already saved.
  3. Select Save connection. You see SSO connection updated.

Some changes need extra steps:

  • Changing the company domain resets verification. Add a new DNS record and verify again.
  • Changing the OIDC issuer isn't possible. Remove the connection and create a new one.

Remove a connection

  1. Select Remove connection.
  2. Read the warning in Remove SSO connection?
  3. Select Remove connection again to confirm. You see SSO connection removed.

Employees stay in the workspace and stay signed in, but they can no longer sign in through your identity provider.

Warning

Before you remove a connection, make sure everyone has another way to sign in. People who only ever used SSO can create a password under Account settings while they're still signed in.

If you leave the Enterprise plan

If the workspace moves off Enterprise, the connection shows Inactive and SSO sign-in stops working. Owners and admins can still remove the inactive connection. Switch back to Enterprise to turn it on again.

Troubleshooting

"SSO is not available for this workspace"

The employee's email domain doesn't match a verified connection, or the workspace isn't on Enterprise. Check the domain is verified and spelled exactly as in their email address.

"Your SSO sign-in could not be completed"

The identity provider didn't send what Hourzero expects. Check, in this order:

  1. The Redirect URI (OIDC) or ACS URL and Entity ID (SAML) in your identity provider match Hourzero's exactly.
  2. The person is assigned to the app in your identity provider.
  3. Their email address in the identity provider is on your company domain.
  4. For SAML: assertions are signed, the certificate hasn't expired, and the email and name attribute names match.

The connection won't save

Read the message under the form. Common causes are a domain with https:// or an @ in it, a domain that already has a connection, or an Issuer URL or SSO URL that doesn't start with https://. If the message says Hourzero can't reach or doesn't trust your identity provider, contact the Hourzero team.

Next steps