SSO for Providers
One login for every integration
Logging in to each tool separately, and tracking down credentials for every one, is a real source of friction. SSO for providers removes it: people sign in once and reach all the integrations and skills their role allows, with no tokens or configuration to manage themselves.
- 01
Skip per-provider logins.
People log in once with their existing credentials and reach every integration they're permitted to use, including magic MCP servers they paste into their agent.
- 02
No credentials to import.
There's no need to import tokens, configs, or secrets to start using an integration. People just sign in and go.
- 03
Stay within your policies.
Access still follows Metorial's access control. People only reach what their role allows.
How it stays in control
Convenient for people, controlled for you
One login across providers is easy for users and still fully governed for administrators.
Built on SSO and SAML
Nothing to share
Managed or your own
What it removes
Access without the busywork
- Logins per personOne
- Tokens to importNone
- Works across connection typesManaged, custom, remote, Docker
- Customer-managed OAuthSupported
Sign in once. Reach every integration. Import no tokens. Stay within your role.
FAQ
Answers to common questions about sso for providers and how they fit into governed AI agent infrastructure.
What is SSO for providers?
It lets people reach all the integrations and skills they're allowed to use with a single login, instead of authenticating to each provider separately.Do people need to import tokens or configs?
No. There's nothing to import. People sign in and start using integrations, with access based on their role.Which integrations does this cover?
It works across first-party integrations, custom MCP servers, remote MCP servers, and Docker MCP servers.Is access still controlled?
Yes. Metorial's policies and access control still apply. People only get access to the integrations and skills they're authorized to use.Who manages the OAuth apps?
By default Metorial manages them. Customer-managed OAuth apps are also supported for enterprises that want more control over their OAuth configuration.How does this work with magic MCP servers?
Magic MCP servers give people a single URL to paste into their agent. SSO handles the sign-in behind that URL. There's nothing else to configure, and access still follows their role.How is this different from SAML?
SAML is how people sign in to Metorial with your identity provider. SSO for providers is about reaching the integrations behind it without logging in to each one. They work together.
