SSO and SCIM are enterprise features and are enabled per organization. See Enterprise features for the rest of the enterprise plan.
SSO
Prerequisites
- An Enterprise plan.
- An IT or identity admin on your team.
- A supported identity provider, for example Microsoft Entra ID, Okta, Google Workspace, or another SAML or OIDC provider your admin already manages.
Setup
1
Ask Firecrawl to enable SSO
Your IT admin contacts Firecrawl support at help@firecrawl.dev and asks to enable SSO for your organization. Firecrawl turns it on and sends setup instructions to the IT contact you name.
2
Configure your identity provider
Firecrawl uses WorkOS for SSO. Your IT admin completes setup in the WorkOS invitation, where they configure your identity provider.
3
Sign in with SSO
When setup is done, team members sign in from the Firecrawl sign-in page using your organization’s SSO.
SCIM directory sync
SCIM directory sync (user provisioning) connects a directory in your identity provider to a Firecrawl team. Firecrawl uses WorkOS Directory Sync, so when people join, change, or leave in your directory, the same change is applied in Firecrawl without manual invites or removals.Prerequisites
- SSO set up for your organization. The User Provisioning (SCIM) tab only appears once your organization has an SSO configuration.
- An identity provider that supports SCIM provisioning, such as Okta, Microsoft Entra ID, or Google Workspace.
- A team admin in Firecrawl to manage provisioning in the dashboard.
Setup
1
Ask Firecrawl to set up directory sync
Contact Firecrawl support at help@firecrawl.dev and ask to enable directory sync. Your IT admin connects your identity provider’s SCIM app through WorkOS, and you receive the WorkOS directory ID for the connection (it looks like
directory_01...).2
Bind the directory to a team
In the dashboard, open Enterprise Controls → User Provisioning (SCIM). Under Directory → team bindings, select the team users should be provisioned into and click Add binding. One organization can bind several directories, each to a different team.
3
Link the directory and enable provisioning
On the binding, paste the WorkOS directory ID and save it, then turn on Enable user provisioning. Directory events are only processed while provisioning is enabled.
4
Map groups to roles
Groups pushed from your identity provider appear under Push groups. For each group, choose a Role (
member or admin) and, optionally, a Team other than the binding team. Groups left as unmapped grant no role. If a user is in several mapped groups, they get the highest role.What gets synced
- New users in the directory are added to the binding team as members, then given the role from their mapped groups.
- Profile updates such as name and avatar are applied to the user. Sign-in email is not changed by directory sync.
- Group membership changes add or remove users from teams that groups are routed to, and update their role.
- Deactivated or deleted users are removed from every team the directory governs. API keys they created are not revoked, because keys belong to the team. Rotate them from the dashboard if needed.

