SSO
Single Sign-On
In short
SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
What is SSO?
SSO, or single sign-on, lets people use one account and one login to reach many applications. Instead of each app keeping its own usernames and passwords, they all trust a central identity provider (IdP), the service that stores accounts and checks credentials. Once you sign in to the IdP, other apps accept that login, so you can open email, chat, and internal tools without typing your password again.
Under the hood, SSO relies on standard protocols. When you visit an app, called the service provider, it redirects you to the IdP; after you authenticate, the IdP sends back a signed assertion, either a SAML response or an OpenID Connect ID token, that proves who you are. The app verifies the signature, creates its own session, and never sees your password. OpenID Connect is built on OAuth 2.0 and is the common choice for modern web and mobile apps, while SAML is widespread in older enterprise software.
A good analogy is a wristband at a music festival: you show your ticket and ID once at the entrance, and staff at each stage simply check the wristband. SSO is used by companies for employee tools, by schools and universities, and in consumer apps that let you sign in with an account you already have.
SSO is often confused with OAuth and with password managers. OAuth is about granting an app permission to access resources, while SSO is about logging in, and OpenID Connect adds that login layer on top of OAuth. A password manager still logs you in to each site separately with different passwords, whereas SSO relies on one identity provider, which becomes a high-value target that must be protected with strong multi-factor authentication.
Key takeaways
- One login at a central identity provider gives access to many applications.
- Apps receive a signed SAML assertion or OpenID Connect ID token, not the user's password.
- OpenID Connect is built on OAuth 2.0; SAML is common in enterprise software.
- Central accounts make it easy to disable a departing user's access everywhere at once.
- The identity provider is a high-value target and needs strong MFA.
Example
// Step 1: redirect the user to the identity provider to log in
const params = new URLSearchParams({
client_id: "my-app",
response_type: "code",
scope: "openid email profile",
redirect_uri: "https://app.example.com/callback",
state: crypto.randomUUID(), // checked on return to prevent CSRF
});
res.redirect(`https://idp.example.com/authorize?${params}`);
// Step 2: at /callback, exchange the code for an ID token, verify its
// signature, and start the app's own session. Production apps also use
// PKCE and a nonce; a well-tested OpenID Connect library handles these steps.Readers ask
Is SSO the same as OAuth?
Not exactly. OAuth 2.0 is a protocol for granting an app limited access to resources, while SSO is the experience of logging in once for many apps. SSO is commonly implemented with OpenID Connect, which adds authentication on top of OAuth 2.0, or with SAML.
Is SSO secure?
SSO can improve security because users manage one strong credential, MFA is enforced in one place, and access can be revoked centrally. The trade-off is that a compromised SSO account opens many doors, so the identity provider must be protected with phishing-resistant MFA.
Often compared
See also
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- SessionBackend & APIs, p. 43A session is a way for a server to remember a user across many requests, usually by keeping their data on the server and giving the browser a session ID.
- SAMLSecurity, p. 36SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- OpenID ConnectSecurity, p. 23OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
Spotted a mistake or something missing on this page?Suggest an edit