Skip to main content
The Identity tab in workspace settings is where workspace owners and admins control how people authenticate to Lovable and how they join the workspace. It brings together domain verification, single sign-on (SSO), SSO enforcement, and automatic user provisioning in one place.
  • Available on: Business and Enterprise plans (SCIM provisioning is Enterprise only)
  • Access: Workspace admins and owners
  • Location: Identity (Settings → Access → Identity)
This page is about how your team signs in to Lovable itself. Apps your team builds can also recognize the signed-in workspace member automatically, so internal tools need no login page of their own. That is a separate feature: see Reuse Lovable workspace identity in your app.

What’s on the Identity tab

User provisioning

The User provisioning section controls how users whose email is on one of your verified domains join the workspace without a manual invite. There are three options.

SSO sign-in

Automatically adds users to your workspace the first time they sign in through your SSO provider (also called just-in-time, or JIT, provisioning). Each provisioned user receives the provider’s JIT role, which you set on the SSO provider. If you haven’t set one, provisioned users join as an editor.
  • On the Enterprise plan, use the SSO Just-in-Time provisioning toggle to turn this on or off yourself.
  • On the Business plan, this is enabled automatically when an SSO provider is configured, and the section shows a read-only Enabled or Disabled status. Contact Lovable support if you need it changed.
  • When no SSO provider is configured yet, the row shows an Add SSO provider button instead.

Verified email sign-up

Automatically adds users who sign up to Lovable with an email on one of your verified domains, whether or not they sign in through SSO. Set the Default role that these users receive when they join.
Verified email sign-up turns on automatically when you verify your first domain, with the default role set to editor. Review the default role after verifying a domain.
Verified email sign-up is unavailable while SCIM provisioning is active, since SCIM manages membership centrally from your identity provider.

Add existing users

A one-time action that adds people who already have Lovable accounts with verified-domain emails to your workspace. Use this after verifying a domain to bring existing colleagues into the workspace in one step, instead of waiting for them to sign in or sign up again. When eligible people exist, Add existing users shows how many Lovable found, for example 12 new users. Click Provision to open a two-step dialog. In Provision users, choose the Domain and the Role to assign, then click Review users. Lovable lists every email address it will add, and Provision 12 users adds them all with that role. Use Back to change the domain or role before you confirm. Provision stays disabled when everyone matching your verified domains already belongs to the workspace.

How provisioning methods interact

  • SCIM takes precedence. When SCIM provisioning is enabled, user creation and role assignment are managed from your identity provider, and verified email sign-up is disabled.
  • Project invites respect provisioning. When you invite someone to a project and their email matches a verified domain with verified email sign-up enabled, they join the workspace as a full member at your default role instead of becoming an external collaborator. When verified email sign-up is disabled, the External project collaborators setting decides whether they are added as collaborators or blocked. See External collaborators.
  • Provisioned members are managed like any other member. They appear in the People tab, where you can change roles, set credit limits, or remove them.

Enforce SSO and session duration

When you have a verified domain and an SSO provider, you can enable Enforce SSO to require all workspace members to sign in through your identity provider, and choose how long SSO sessions last (8 hours, 24 hours, 48 hours, or 7 days) before members must re-authenticate. For setup steps, the external-collaborator removal option, and troubleshooting, see Set up workspace single sign-on (SSO). Enforce SSO applies only to this workspace. To also control how people on your domain create accounts and workspaces, see Restrict a domain to SSO (domain lock).
To require a second factor without enforcing SSO, Enterprise workspaces can instead require two-factor authentication for everyone accessing the workspace. The two settings are mutually exclusive. When you enable Enforce SSO, Lovable automatically disables Require two-factor authentication, since your identity provider handles multi-factor authentication for enforced SSO sessions.

Restrict a domain to SSO (domain lock)

Domain lock is the term Lovable support uses for a combination of settings that tie a verified domain to your identity provider, so everyone on the domain signs in through SSO and works only in your workspaces. It is not a single setting. You configure two of the settings per workspace. The other two apply to the whole domain, including any other workspace that has verified it. Lovable support enables the two domain-wide settings for workspaces on the Enterprise plan. Require SSO and Enforce SSO are different settings. Enforce SSO is a workspace setting. It decides who can access this workspace, and someone on your domain can still create a Lovable account with a password and use it in other workspaces. Require SSO is a domain setting. It decides how people on the domain create accounts, so a new user on acme.com can only create an account through your SSO provider. A locked domain uses both. Set up the settings in this order.
  1. Verify your domain.
  2. Add and test your SSO provider. See Set up workspace single sign-on (SSO).
  3. Enable SSO sign-in or Verified email sign-up under User provisioning. Without provisioning, a new user on a locked domain signs up, sees that they are not a member of any workspace, and cannot create one.
  4. Enable Enforce SSO. The toggle becomes available six hours after you add the provider.
  5. Contact Lovable support to enable Require SSO and Block workspace creation for the domain.
If another workspace verifies the same domain, the two domain-wide settings already apply to it. You set up verification, the SSO provider, provisioning, and Enforce SSO in each workspace separately.

Removal and cascade behavior

Identity settings depend on each other, so removing one piece can turn others off:
  • Deleting your last verified domain automatically disables Enforce SSO and Verified email sign-up.
  • Deleting your SSO provider automatically disables Enforce SSO, removes SCIM provisioning, and disables Require SSO and Block workspace creation for this workspace’s verified domains. See Restrict a domain to SSO (domain lock).
Lovable shows the effects in the confirmation dialog before you delete. Existing members keep their access in all cases.

FAQ

Both add verified-domain users automatically, but they trigger differently. SSO sign-in adds users when they first authenticate through your SSO provider and assigns the provider’s JIT role. Verified email sign-up adds users when they sign up with a verified-domain email using any sign-in method, no SSO required, and assigns the default role you set. You can use both at once.
The self-serve toggle is available on the Enterprise plan. On the Business plan, SSO sign-in provisioning is enabled automatically when an SSO provider is configured, and the status is shown read-only.
Verified email sign-up is disabled while SCIM provisioning is active, because SCIM manages workspace membership centrally from your identity provider. Disable SCIM if you want to switch to domain-based provisioning.
No. Turning off SSO sign-in, verified email sign-up, or SCIM only stops new automatic joins. Members who already joined keep their access until you remove them from the People tab.
Users added through SSO sign-in get the JIT role set on your SSO provider, or join as an editor if no JIT role is set. Users added through verified email sign-up get the default role set in the User provisioning section. Users provisioned through SCIM get roles from your group mappings, or the SCIM default role. You can change any member’s role afterward from the People tab.
No. Enforce SSO applies only to the workspace where it is enabled. Someone on your domain can still create a Lovable account with a password and create their own workspace. Require SSO and Block workspace creation cover those two cases. Both apply to the whole domain on the Enterprise plan, and Lovable support enables them for you. See Restrict a domain to SSO (domain lock).