SAML SSO
Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.
跳转到常见问题注意: 此功能仅适用于商业版或企业版用户。
With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.
To use SSO with Notion:
Your workspace must be on a Business Plan or Enterprise Plan.
Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →
A workspace owner must configure SAML SSO for the Notion workspace.
At least one domain must be verified by a workspace owner. Learn more about domain verification →
注意:只有工作空间成员可以使用 SAML 单点登录进行登录。受邀访问已启用 SAML 的 Notion 工作空间页面的访客无法使用 SAML 单点登录。他们需要使用其他登录方式,例如用户名和密码,或通过 Google 或 Apple 登录。
Business Plan
To set up SAML SSO for a Business workspace, a workspace owner can:
Go to
Settings→General.In the
Allowed email domainssection, remove all email domains.Select the
Identitytab inSettings.
Verify one or more domains. See instructions for domain verification here →
Toggle on
Enable SAML SSOand the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.The SAML SSO Configuration modal is divided into two parts:
The
Assertion Consumer Service (ACS) URLneeds to be entered in your Identity Provider (IdP) portal.The
Identity Provider Detailsis a field in which you need to provide either an IdP URL or IdP metadata XML.
Choose how people sign in and whether new accounts are created for them, then select
Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Enterprise Plan
Enterprise Plan organization owners can manage SAML SSO for their workspace (or multiple workspaces belonging to their organization) by following these steps:
Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →
In the
Generaltab of your organization settings, toggle onEnable SAML SSO.Choose a setup method (URL or metadata XML), paste the required information from your Identity Provider or IdP, and select
Save & enable. You can also pick how people sign in and turn on automatic account creation before you save, so everything takes effect at once.
注意: 目前,企业版的组织只能设置一个 SAML SSO 身份提供商。
Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.
You can pick this while you are first setting up SAML, in the same save. You can also change it later.
If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.
On the Business Plan, this will look like this:

On the Enterprise Plan, this will look like this:

SSO bypass
In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.
If a SAML configuration is managed at the organization level, only organization owners will be able to bypass SSO.
If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.
注意:此功能仅适用于企业版用户。启用此功能无需进行域名验证。
Workspace-level SAML authorization allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.
To enable workspace-level SAML authorization:
Open the workspace switcher and select
Manage organization. You may need toSet up organizationfirst if you haven’t already. Learn more here →In the
Generaltab of your organization settings, toggle onRequire SAML authorization for workspace access.
注意:在启用前,请确保所有成员已被添加到你的身份提供商 (IdP) 中,以避免意外无法访问工作空间。
When enabled, members of the affected workspaces who haven’t already authorized with your organization’s IdP will be met with an additional authorization screen. They’ll need to go through SAML SSO to continue viewing your organization’s workspaces.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.
To enable Just-in-Time provisioning if you're on the Business Plan, go to Settings → Identity and make sure that Automatic account creation is enabled.
To enable Just-in-Time provisioning if you’re on the Enterprise Plan, go to your organization settings → General and make sure that Automatic account creation is enabled.
提示:如果你正在使用 SCIM,我们不建议启用即时 (Just-in Time) 配置。设置“已授权电子邮件域”后,该域的用户即可加入工作空间,因此可能会导致其在身份提供商和 Notion 之间的成员资格不匹配。
常见问题
为什么我无法启用 SAML 单点登录?
为什么我无法启用 SAML 单点登录?
最常见的原因是你还没有验证域的所有权。如果是这种情况,你会发现“验证电子邮件域”部分中没有列出任何域,或者域处于待验证状态。
关于后续步骤,请参阅此处关于如何完成域验证的指令 →
为什么我无法编辑我的 SAML 单点登录设置?
为什么我无法编辑我的 SAML 单点登录设置?
你可能正在尝试从已经关联到另一个 SSO 配置的链接工作空间修改已验证的域或 SSO 配置。
在链接工作空间中,所有域名管理和 SSO 配置设置均为只读。要修改 SSO 配置或将此工作空间从 SSO 配置中移除,你必须拥有对主要工作空间的访问权限。主要工作空间的名称可以在设置中的 身份与配置选项卡顶部找到。
为什么我需要验证域才能启用 SSO?
为什么我需要验证域才能启用 SSO?
我们需要验证电子邮件域的所有权,以确保只有域所有者能自定义用户登录 Notion 的方式。
我在设置 SSO 时遇到问题。
我在设置 SSO 时遇到问题。
尝试使用 URL 而不是 XML。
在强制用户使用之前,请先用测试帐号测试设置过程。
如果以上方法都没能解决问题,请联系支持团队:
为什么在为我的工作空间配置 SAML 单点登录之前,我应该先从“已授权电子邮件域”设置中删除电子邮件域?
为什么在为我的工作空间配置 SAML 单点登录之前,我应该先从“已授权电子邮件域”设置中删除电子邮件域?
已授权电子邮件域设置允许具有所选域的用户在未经通过 IdP 配置的情况下访问你的工作空间。为确保只有通过 IdP 配置的用户才能访问启用了 SAML 的工作空间,请从 已授权电子邮件域 列表中删除所有电子邮件地址以禁用此功能。
如果我的身份提供商 (IdP) 暂时不可用,我还能登录 Notion 吗?
如果我的身份提供商 (IdP) 暂时不可用,我还能登录 Notion 吗?
是的,即使 SAML 被强制使用,工作空间所有者仍可以选择用(电子)邮件登录。工作空间所有者可以更改 SAML 配置,禁用强制使用 SAML,这样用户就能再次用(电子)邮件登录。
如何允许我 SAML 配置中其他工作空间的管理员创建新工作空间?
如何允许我 SAML 配置中其他工作空间的管理员创建新工作空间?
只有主要工作空间的管理员才能使用你已验证的域名创建新工作空间。请联系支持团队 (team@makenotion.com) 将你的主要 SAML 单点登录工作空间切换为你 SAML 配置中链接的另一个工作空间。
Do I have to save my SAML settings twice?
Do I have to save my SAML settings twice?
No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.
