devlin.ai has two ways to add security to sign-in beyond the email code, Google and Microsoft options. Two-factor authentication is something each person turns on for their own account, on all plans: after signing in, they also enter a code from an authenticator app. SAML single sign-on (SSO) sends everyone at your company's email domain to your company's identity provider to sign in. SSO is available on these plans: Enterprise. It is set up for your organization by the devlin.ai team, not from a settings screen.
Before you start
- Two-factor authentication needs an authenticator app on a phone or computer. Setup shows a QR code to scan with it, and names Google Authenticator, 1Password and Authy as examples.
- Two-factor authentication is a personal setting. There is no workspace setting that requires members to turn it on. An organization that needs to require a second factor for everyone does it through SSO and its identity provider.
- SSO has no self-serve setup. A connection links your identity provider and one or more email domains to your organization, and only the devlin.ai team can create or change it. Contact devlin.ai support to start.
- If your account signs in through SSO, the Two-factor authentication section in your account settings has no setup controls. It tells you that sign-in security, including any two-factor requirement, is managed by your organization's identity provider. If the account still has an authenticator device from before SSO, the section also lists that device with Remove, because a sign-in that does not go through SSO is still asked for its code. Removing it works from a session that has entered that code.
How SAML SSO works
Signing in
There is no separate SSO button on the sign-in page. Enter your work email and select Continue. devlin.ai looks at the domain of the address, which is everything after the @ sign. If that domain belongs to an SSO connection, you are sent to your company's identity provider to sign in, and no email code is sent. When you come back, you land on the page you were trying to open.
The domain has to match one of the connection's domains exactly. A subdomain is a different domain and has to be listed on the connection itself.
SSO only works while the organization is on a plan that includes it (Enterprise). If the organization moves to another plan, its domains stop being sent to the identity provider, new people are no longer added automatically, and SSO is no longer required.
Joining the organization
The first time someone signs in through SSO, they are added to the organization automatically. They do not need an invitation.
- They get the default role chosen for the connection, which is either member or admin. Unless the connection was set up otherwise, it is member.
- If there is a pending invitation for their email address that has not expired, they get the role on that invitation instead, and the invitation is marked as accepted.
- If the organization has a seat limit, joining needs a free seat. Active members and pending invitations both count as taken seats. If no seat is free, the person is signed out and the sign-in page shows Seat limit reached, asking them to contact their administrator.
- If adding the person fails for another reason, they are signed out and the sign-in page shows a message that the account could not finish being set up. Signing in again retries it.
Only a sign-in through the identity provider adds someone this way. A person at your domain who signs in with Google or Microsoft does not join the organization automatically. See Members and roles for invitations and roles, and Workspaces for how an organization differs from a personal workspace.
Requiring SSO
A connection can be set to require SSO. It is not required unless the devlin.ai team turns that on for your connection.
When SSO is not required, it is one more sign-in method. Entering a work email still goes to the identity provider, but Sign in with Google and Sign in with Microsoft keep working for those addresses, and if single sign-on cannot be started the sign-in page sends an email code instead.
When SSO is required:
- An account with an email address at one of the connection's domains has to be one that signs in through your identity provider. If such an account gets in another way, for example with Sign in with Google, it is signed out as soon as it opens any page in the app and returned to the sign-in page, which shows Single sign-on required.
- On that page the Google and Microsoft buttons are hidden. Enter your work email and select Continue to go to your identity provider.
- If single sign-on cannot be started, the sign-in page does not fall back to an email code. It shows "We couldn't start single sign-on. Use your company login or contact your administrator."
- The organization's simulations, coaches, results and settings are also blocked for that account at the data level, not only in the app's pages.
- Accepting an invitation is blocked in the same way, with the message "Your organization requires single sign-on. Sign in through your organization's SSO, then open this invitation again."
The requirement follows the email domain, not membership. It applies to every account at the connection's domains, and it does not apply to members of your organization whose email is at another domain, such as an outside contractor you invited. They keep signing in with an email code, Google or Microsoft.
Steps
These steps turn on two-factor authentication for your own account.
- Open Settings → Account and find the Two-factor authentication section.
- In Device name, type a name that tells you which device or app this is, up to 64 characters. You cannot reuse a name you already gave another device.
- Select Add authenticator app. A QR code appears.
- Scan the QR code with your authenticator app. If you cannot scan it, type the key shown under the QR code into the app instead.
- Enter the code the app shows and select Confirm. Select Cancel instead to stop without turning anything on.
Result
The section shows "Two-factor authentication is on." and lists the device by its name. Nothing changes until you confirm a code: a setup you started and did not finish does not affect how you sign in.
From now on, each time you sign in with an email code, Google or Microsoft, devlin.ai asks for a code from your authenticator app before it opens any page of the app. The browser you used for setup is already verified. Any other browser where you were signed in is asked for a code the next time it loads a page.
Signing in with two-factor authentication
After you sign in, the Two-factor authentication page asks you to enter the code from your authenticator app.
- If you have more than one device, choose the one you are using under Device.
- Enter the code and select Verify.
You then continue to the page you were opening. If the code is wrong, the page shows "That code didn't work. Try again." After several attempts in a short time it shows "Too many attempts. Wait a minute and try again."
Sign in with a different account signs you out and returns you to the sign-in page.
A session that signed in through SAML SSO is never asked for this code, even if the account has an authenticator device. For those sessions the identity provider is responsible for any second factor.
Backup devices, removing a device and losing one
- To add a backup: with one device set up, the section suggests adding a second. Repeat the steps above with another device name. At sign-in you can then choose either device.
- To remove a device: select Remove next to the device, then Yes, remove. Removing your last device turns two-factor authentication off, and you are no longer asked for a code at sign-in.
- If you lose a device: if you still have a second device, sign in with it, remove the lost one and add a new one. If you lose your only device, you cannot get past the code page yourself. Contact devlin.ai support to regain access.