Skip to content →

SAML

Customers can opt to enable SAML for their workspace to manage logins through an Identity Provider.

Available to workspaces on our Enterprise plan
Login screen on the Linear desktop app

Overview

We currently support most identity providers (Okta, OneLogin, LastPass, Auth0, Bitum, etc.). If you don't use SAML, the Enterprise plan also lets you remove the "login via email" authentication option so that users in your workspace must login with Google SSO.

Once SAML is enabled, all members in your workspace will be required to login via SAML. They can login via your identity provider's website or by clicking the option to Sign in with SAML/SSO on the Linear login page. They will not be able to load Linear if they try to login with Google or email. Guests are an exception, who will be able to sign in with "login via email". Admins can log in through any method to prevent lockouts.

Configure

Upgrade to the Enterprise plan

To enable SAML, you'll need to contact us for the Enterprise plan from Settings > Workspace > Plans. If you're moving from an existing plan to the Enterprise plan, your current subscription will be canceled and a credit will be applied to the new Enterprise plan subscription.

Configuration

Linear offers a self-serve SAML configuration available from Settings > Workspace > Security. From here, you can paste in an XML URL or the raw XML text to connect with your identity provider. If you're not sure where to find this in your identity provider, take a look at their documentation or reach out to us for help.

Once you have added this information, you can add approved domains for logging in with SAML. You will need to provide an email for our verification process when adding a new domain.

Enable and test

Once your XML data and approved domains are added, you can toggle on SAML authentication. This will disable any other login method type by default.
You can have SAML as optional by enabling Google or Email login or you can choose to allow non-SAML logins only for other email domains (ideal for contractors or guests). Admin members of your workspace will still be able to login using email in all cases in case SAML is causing issues and needs to be turned off.

User sessions won't be logged out or notified at the time of enabling, but the next time they sign in they will have to use SAML to regain access.

Disable new workspace creation

Once SAML is enabled, you have the option to prevent non-admins from creating new Linear workspaces with their email credential from the domain you claimed during setup. This can be useful to make sure all work is consolidated in a single Linear workspace.

FAQ

If SAML is enabled for your workspace, you must login via your SAML service's website or by selecting the SAML login option on the Linear login page (it's a bit small and in gray letters, right under the other options).

If you're getting an error about the workspace not being accessible and it is your first time logging into Linear with SAML, please try logging out of the SAML provider and then logging in.

If you get repeated errors, then please contact support.

For SAML-enabled Workspaces, make sure that members are given access in your identity provider(IdP). New members will be automatically provisioned using Just-In-Time (JIT) provisioning and an account will be created for them so long as they have access through your IdP.
Existing Linear members that have the correct IdP permissions can simply sign in using the SAML SSO option.

We support enabling SCIM 2.0 for you on the Enterprise plan if you have SAML enabled. More details here.

Guests must be invited over email to make sure they're permissioned appropriately. In order to invite them, enable the toggle pictured and then choose "Invite" in Settings > Workspace > Members.

Security > Allow other authentication methods for all additional email domains > On