# Set up SSO with OpenID Connect (/docs/support/security/single-sign-on/set-up-sso-with-openid-connect)

Circleback works with any identity provider that supports OpenID Connect (OIDC), so your team can sign in with the provider your company already uses.

You need to be a Circleback workspace admin and have access to manage applications in your identity provider. See [Set up single sign-on](/docs/support/security/single-sign-on/sso) for workspace requirements.

If you're connecting with SAML instead, follow the [SAML guide](/docs/support/security/single-sign-on/set-up-sso-with-saml).

## Create an OIDC application

Keep Circleback and your provider's admin console open in separate tabs as you set up the connection. Field names may vary by provider.

1. In Circleback, go to Settings → General (under Workspace).
2. Under **Single sign-on**, select **Connect**. Choose **OIDC**, then select **Continue**.
3. In your provider's admin console, create an OpenID Connect application named **Circleback**.
4. Copy the **Callback URL** from Circleback into your provider's callback or redirect URL field: `https://circleback.ai/api/sso/oauth/oidc`.
5. Copy the application's **Client ID** and **Client secret** into the matching fields in Circleback. Keep the client secret private.
6. Copy your provider's **Discovery URL** into Circleback. This must use HTTPS and usually ends in `/.well-known/openid-configuration`. Use the URL for the tenant or authorization server where you created the application; you can find it in your provider's documentation.
7. In your provider, give the people or groups who should use Circleback access to the application.
8. Return to Circleback and select **Continue**.
9. Leave **No directory sync** selected if you only need SSO, or choose a directory provider to set up SCIM provisioning. Select **Connect**.

If you chose a directory provider, use the credentials shown in Circleback to [set up directory sync](/docs/support/security/single-sign-on/sso).

To require everyone in your workspace to log in with SSO, follow [Enforce SSO for your workspace](/docs/support/security/single-sign-on/sso).