Enterprise SSO
Your team can sign in to Spark Memory with the company accounts they already have. We support Microsoft Entra ID alongside Solder Spark accounts, and everyone who signs in through it is governed exactly like everyone else. Your sign-in policy applies, roles apply, disabling an account ends its sessions, and every login lands in your organization's audit log with the provider named.
What you get#
- One place to grant access and one place to remove it. Your identity provider decides who can sign in, and your Spark Memory organization decides what they can do once inside.
- A Log in with Microsoft button on the sign-in page for your people.
- Sign-out clears the Spark Memory session. Your own Entra session policies keep governing the Microsoft side.
Setting it up#
Setup takes a few minutes in the Microsoft Entra admin center, on your side.
- Under App registrations, choose New registration and pick single tenant.
- Set the Web redirect URI to
https://ai.solderspark.com/auth/callback - Under Certificates and secrets, create a client secret.
- Add the delegated permissions
openid,profile, andemail. These are granted by default for sign-in.
Then contact us at contact@solderspark.com with your tenant ID and application (client) ID, and we will enable the connection for your organization. The client secret is collected through a secure channel, never by email.
Claiming your domain#
Pair SSO with a claimed company domain, under Company domains on your organization page. Claiming a domain takes a short proof of ownership. We give you a TXT record to add where you manage the domain's DNS, and once we see it the claim goes live and sign-ins from that domain join your organization automatically. Domain claims are part of the Team plan.
Entra proves the identity, and your organization's policy decides who belongs. A person who has both a Microsoft account and a Solder Spark account is treated as two separate accounts. Pick the one your organization uses and disable the other from the Members table.