Security
Protect your account and your workspace.
- Two-factor authentication (2FA)Protect your Tinct account with a code from an authenticator app.
- Require two-factor authentication in your workspaceMake two-factor authentication mandatory for every member of your workspace.
- Single sign-on (SSO) for your workspaceConnect your own identity provider so your team signs in to Tinct the way they sign in everywhere else.
- Verify your email domainProve that your company owns an email domain with a DNS TXT record, so single sign-on can cover it.
- Set up SSO with OpenID ConnectConnect an OpenID Connect identity provider: the values to exchange, the test sign-in, and how to enable it.
- Set up SSO with SAML 2.0Connect a SAML 2.0 identity provider, and manage its signing certificates and their rotation.
- Require SSO in your workspaceMake your identity provider the only way into your workspace, and know who is affected and how to get back in.
- Sign in with SSOHow to sign in when your company uses single sign-on, and what the error messages mean.
- Set up SSO with KeycloakConnect Keycloak to Tinct with OpenID Connect or SAML 2.0: what to set on each side.
- Set up SSO with Amazon CognitoConnect an Amazon Cognito user pool to Tinct with OpenID Connect: what to set on each side.
- Set up SSO with Google WorkspaceConnect Google Workspace to Tinct with OpenID Connect or SAML 2.0: what to set on each side.
- Set up SSO with OktaConnect Okta to Tinct with OpenID Connect or SAML 2.0: what to set on each side.
- Set up SSO with Microsoft Entra IDConnect Microsoft Entra ID to Tinct with OpenID Connect or SAML 2.0: what to set on each side.
- Set up automatic provisioning (SCIM)Let your identity provider add, update and deactivate your members automatically, with Okta and Microsoft Entra ID steps.
- Manage roles with directory groupsPush groups from your directory and map them to workspace roles.