SSO login (original) (raw)

Claude for Government requires Single Sign-on (SSO) for user authentication. Unlike the commercial Claude Enterprise plan, email based (magic link) login is only available to the Primary Owner during account setup. All other users must authenticate through your organization's identity provider (IdP).

Once SSO is configured, the Primary Owner can disable magic link login entirely so that all authentication flows through your IdP.

How SSO differs for Claude for Government

Steps for setting up SSO

Prerequisites

Before you begin, confirm that you have:

Step 1: Sign in as Primary Owner

Step 2: Verify your domain

Before configuring your Identity Provider (IdP), you must verify ownership of your login domain.

Step 3: Configure your Identity Provider

Anthropic acts as the Service Provider (SP) in the SAML SSO flow. Your organization’s IdP (e.g., Entra or Okta) acts as the Identity Provider.

Step 4: Configure Anthropic with your IdP details

Once your SAML application is set up in your IdP, provide Anthropic with the details it needs to verify SAML assertions. On the identity settings page, enter:

Troubleshooting attribute mappings

Attribute mapping is where most configuration issues occur. If login fails after setup:

Step 5: Test and finalize

After SSO is configured, any user assigned to the SAML application in your IdP can log in and will be provisioned a seat automatically, provided your organization has available licenses. If no seats are available, users will see an error at login. Contact your Anthropic account representative to add licenses. For more controlled provisioning—including role assignment and multi-organization support—see SCIM provisioning.


Related Articles

Set up single sign-on (SSO)Set up JIT or SCIM provisioningGoogle Workspace SSO setupPing Identity SSO setupSet up SCIM in Claude for Government