SAML SSO
Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.
跳至常見問題提示: 此功能僅適用於商業版或企業版的使用者。
With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.
To use SSO with Notion:
Your workspace must be on a Business Plan or Enterprise Plan.
Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →
A workspace owner must configure SAML SSO for the Notion workspace.
At least one domain must be verified by a workspace owner. Learn more about domain verification →
提示: 只有工作空間成員可以使用 SAML 單一登入進行登入。受邀至已啟用 SAML 的 Notion 工作空間頁面的訪客無法使用 SAML 單一登入進行登入。他們需要改用其他登入方式,例如使用者名稱和密碼,或是透過 Google 或 Apple 登入。
Business Plan
To set up SAML SSO for a Business workspace, a workspace owner can:
Go to
Settings→General.In the
Allowed email domainssection, remove all email domains.Select the
Identitytab inSettings.
Verify one or more domains. See instructions for domain verification here →
Toggle on
Enable SAML SSOand the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.The SAML SSO Configuration modal is divided into two parts:
The
Assertion Consumer Service (ACS) URLneeds to be entered in your Identity Provider (IdP) portal.The
Identity Provider Detailsis a field in which you need to provide either an IdP URL or IdP metadata XML.
Choose how people sign in and whether new accounts are created for them, then select
Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Enterprise Plan
Enterprise Plan organization owners can manage SAML SSO for their workspace (or multiple workspaces belonging to their organization) by following these steps:
Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →
In the
Generaltab of your organization settings, toggle onEnable SAML SSO.Choose a setup method (URL or metadata XML), paste the required information from your Identity Provider or IdP, and select
Save & enable. You can also pick how people sign in and turn on automatic account creation before you save, so everything takes effect at once.
提示: 目前,企業版的組織只能設定一個 SAML SSO 身分識別提供者 (IdP)。
Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.
You can pick this while you are first setting up SAML, in the same save. You can also change it later.
If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.
On the Business Plan, this will look like this:

On the Enterprise Plan, this will look like this:

SSO bypass
In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.
If a SAML configuration is managed at the organization level, only organization owners will be able to bypass SSO.
If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.
提示:此功能僅適用於企業版的使用者。啟用此功能不需要進行網域驗證。
Workspace-level SAML authorization allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.
To enable workspace-level SAML authorization:
Open the workspace switcher and select
Manage organization. You may need toSet up organizationfirst if you haven’t already. Learn more here →In the
Generaltab of your organization settings, toggle onRequire SAML authorization for workspace access.
提示: 在啟用之前,請確保所有成員都已新增至您的身分提供者 (IdP),以防止意外無法存取工作空間。
When enabled, members of the affected workspaces who haven’t already authorized with your organization’s IdP will be met with an additional authorization screen. They’ll need to go through SAML SSO to continue viewing your organization’s workspaces.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.
To enable Just-in-Time provisioning if you're on the Business Plan, go to Settings → Identity and make sure that Automatic account creation is enabled.
To enable Just-in-Time provisioning if you’re on the Enterprise Plan, go to your organization settings → General and make sure that Automatic account creation is enabled.
提示: 如果您正在使用 SCIM,我們不建議啟用即時 (Just-in-Time) 佈建。設定「已允許的電子郵件網域」會允許該網域上的使用者加入工作空間,因此其身分提供者中的成員資格與 Notion 可能會不一致。
常見問題
為什麼我無法啟用 SAML 單一登入?
為什麼我無法啟用 SAML 單一登入?
最常見的原因是您尚未驗證網域的所有權。如果是這種情況,您會發現「驗證電子郵件網域」部分中沒有列出任何網域,或者網域正在等待驗證。
關於後續步驟,請參閱此處關於如何完成網域驗證的說明 →
為什麼我無法編輯我的 SAML 單一登入設定?
為什麼我無法編輯我的 SAML 單一登入設定?
您可能正嘗試從已連結的工作空間修改已驗證網域或單一登入配置,但該工作空間已與另一組單一登入配置關聯。
於連結工作空間中,所有網域管理與單一登入配置設定皆為唯讀。若要修改單一登入配置或將此工作空間從單一登入配置中移除,您必須具備主要工作空間的存取權限。主要工作空間的名稱位於您設定中 身分與佈建分頁的頂端。
為什麼我需要驗證網域才能啟用單一登入?
為什麼我需要驗證網域才能啟用單一登入?
我們要求驗證電子郵件網域的所有權,以確保只有網域擁有者可以自訂其使用者登入 Notion 的方式。
我在設定單一登入時遇到問題。
我在設定單一登入時遇到問題。
請嘗試使用 URL 而非 XML。
在對使用者強制執行之前,請先使用測試帳號測試設定流程。
如果這些選項都無法解決問題,請聯繫支援團隊:
為什麼在為我的工作空間設定 SAML 單一登入之前,我應該從「已允許的電子郵件網域」設定中移除電子郵件網域?
為什麼在為我的工作空間設定 SAML 單一登入之前,我應該從「已允許的電子郵件網域」設定中移除電子郵件網域?
已允許的電子郵件網域設定允許擁有選定網域的使用者在未經由您的 IdP 佈建的情況下存取您的工作空間。為確保只有經由您的 IdP 佈建的使用者才能存取您已啟用 SAML 單一登入的工作空間,請透過從已允許的電子郵件網域列表中移除所有電子郵件地址來停用此功能。
如果我的身分識別提供者 (IdP) 無法使用,我還能登入 Notion 嗎?
如果我的身分識別提供者 (IdP) 無法使用,我還能登入 Notion 嗎?
是的,即使強制執行 SAML,工作空間擁有者仍可選擇使用電子郵件登入。工作空間擁有者可以變更 SAML 設定以停用 強制執行 SAML,這樣使用者就能再次使用電子郵件登入。
我該如何允許我 SAML 單一登入設定中其他工作空間的管理員建立新的工作空間?
我該如何允許我 SAML 單一登入設定中其他工作空間的管理員建立新的工作空間?
只有您主要工作空間的管理員才能利用您已驗證的網域建立新的工作空間。請聯繫我們的支援團隊 (team@makenotion.com),將您的主要 SAML 單一登入工作空間切換至您 SAML 單一登入設定中的另一個連結工作空間。
Do I have to save my SAML settings twice?
Do I have to save my SAML settings twice?
No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.
