SSO FAQs
Why do I see the error "SSO is not configured for this domain" when trying to sign in?
The "SSO is not configured for this domain" error tells you that your email address is not in a verified domain. A verified domain is a domain that is verified and configured for SSO in your workspace settings. Only users with email addresses in your verified domain(s) can sign in through SSO. For example, if you verified example.com, only users with emails like user@example.com can sign in through the SSO page.
How do I verify my domain for SSO?
For NocoDB Cloud (Both Business and Enterprise Plans):
- Open the domain verification section:
- Business Plan: In the workspace sidebar, go to Settings > Single Sign-On (SSO). Use the Domain section.
- Enterprise Plan: Go to Account Settings > Authentication > Domain Verification.
- Enter your domain (for example,
example.com). - Copy the TXT record that NocoDB gives.
- Add the TXT record to the DNS of your domain, through your registrar or DNS provider.
- Wait for DNS propagation. This can take from a few minutes to several hours.
- Click the Verify button in NocoDB. NocoDB confirms that you own the domain.
For NocoDB Self-hosted/On-prem: Domain verification is not necessary. Configure SSO providers directly, without DNS verification.
Do I need to verify my domain when setting up SSO (e.g., Google OAuth)?
For NocoDB Cloud (Both Business and Enterprise Plans): Yes. You must configure Google OAuth or other SSO providers, and you must also verify your domain in the SSO settings. To verify the domain, add it and then add the TXT record that NocoDB gives to your DNS. Users from that domain can sign in through SSO only after domain verification.
For NocoDB Self-hosted/On-prem: Domain verification is not necessary. You can configure SSO providers without DNS verification of your domain.
When should I verify my domain?
For Cloud users (both Business and Enterprise plans), complete the domain verification before you configure SSO providers (Google OAuth, SAML, OIDC). Domain verification makes sure that:
- Only users with email addresses from your verified domain can access the workspace.
- SSO providers are correctly configured with domain restrictions.
- The authentication flow works correctly for the users of your organization.
If you configure SSO without domain verification, errors can occur. Also, users from domains that are not verified possibly cannot sign in.
Why does domain verification fail even after adding the TXT record?
DNS propagation can take time. After you add the TXT record to the DNS settings of your domain:
- Typical propagation time: 5-30 minutes
- Maximum propagation time: Up to 24-48 hours (rare)
- Check propagation: Use online DNS lookup tools. Make sure that the TXT record is visible.
- Retry verification: If verification fails, wait a few minutes and try again.
If verification fails after 24 hours, make sure that you added the TXT record correctly. If the problem continues, contact your DNS provider.
Why do I get a redirection/callback URL or URI error when setting up SSO?
A redirect or callback URL error during SSO setup usually has one cause. The Redirect URL in your identity provider is not exactly the same as the Redirect URL from NocoDB. The Redirect URL is sometimes called Callback URL or Redirect URI. Common reasons are:
- A typo or extra spaces in the URL/URI
- HTTP in place of HTTPS (or the opposite)
- The full path is not included
- The wrong environment is registered (for example, a local URL for production)
- The Redirect URL is not updated after a change to your NocoDB domain
Solution: Always copy the exact Redirect URL/URI from NocoDB and paste it into the configuration of your identity provider. Any difference causes an error during authentication.
How do API tokens work with SSO-enabled workspaces?
When a workspace enforces Single Sign-On (SSO), only tokens generated in an authenticated SSO session have API access. For more information, refer to API Tokens with SSO.
Last updated on