Skip to content

Domains and enterprise federation

View as Markdown

Developer resources on Sudomimus belong to organizations. An organization owns its applications, sectors, adopted domains, login policies, and federation connectors. Organization owners can verify domain control, configure how users on those domains sign in, and connect a corporate identity provider.

This section explains domain adoption, domain login policies, and federation connectors. Each feature can be used independently when its prerequisites are met.

Step What it is Who it is for
1. Adopt a domain Prove you control a domain (example.com) via a DNS TXT record; the platform binds it exclusively to your organization. Any organization that owns a domain.
2. Set a login policy For users whose email is on that verified domain, decide platform-wide whether logins are allowed, blocked, or forced through SSO. Organizations that want to govern how their domain’s users authenticate.
3. Federate to your IdP Register your organization’s OIDC or SAML identity provider as a connector, then either offer it as a “Sign in with …” button on an application or force a domain’s users through it. Companies and communities that run their own IdP (Entra ID, Okta, Google Workspace, …).

Each step stands on its own. Adopting a domain is valuable purely as a verified, organization-owned claim. A login policy needs nothing more than a verified domain. Federation adds the IdP. You only go as far down this path as your needs require.

Everything here hangs off an organization — the multi-tenant container that owns applications, sectors, domains, and connectors. An account becomes an organization owner by creating an organization from the With portal. Membership carries a role (VIEWER < ADMIN < OWNER); the mutations in this section are owner-only, and several of them — setting a login policy, disabling an organization’s domain federation — require the caller to be the organization’s sole owner, so one co-owner cannot unilaterally change how everyone on a shared domain signs in.

These features are available in the With portal at with.sudomimus.com.

Start by adopting a domain