Docs
Single sign-on (SSO)
Let your team sign in with your company identity provider (Microsoft Entra, Google Workspace, Okta) over OpenID Connect.
What SSO gives you
Single sign-on lets everyone on your team sign in to CrunchJunkie with your existing company identity provider — Microsoft Entra ID (Azure AD), Google Workspace, Okta, or any OpenID Connect provider — instead of a separate password. New teammates are provisioned into your workspace automatically the first time they log in. SSO is available on paid plans (Pro, Agency, Scale) and is configured by a workspace owner or admin under Settings → SSO.
We support OpenID Connect today, which covers the large majority of enterprise IdPs. (SAML-only providers are on the roadmap.)
Register CrunchJunkie in your IdP
In your identity provider, create a new OIDC (OpenID Connect) application. Set the redirect URI to the value shown in Settings → SSO — it looks like https://app.crunchjunkie.io/api/auth/sso/callback. Request the standard scopes openid, email and profile.
Your IdP will give you three things: an issuer URL, a client ID and a client secret. Paste them into Settings → SSO and save. The secret is stored encrypted and never shown back to you — to change it, just save a new one.
Verify your email domains
SSO routes a login by the user's email domain, so you tell us which domains belong to you and prove you own them. Add a domain (e.g. acme.com) in Settings → SSO and we'll show a DNS TXT record — add it to that domain's DNS, then click Verify. A domain routes no logins until it's verified, and each domain can belong to only one workspace, so no one else can claim yours.
Turn it on
Once at least one domain is verified, enable SSO. From then on, a user goes to your login page, chooses single sign-on, enters their work email, and is sent to your IdP; after they authenticate there, they land back in CrunchJunkie signed in. The first time someone from a verified domain signs in, they're added to your workspace automatically.
Behind the scenes we validate the identity provider's signed token (its signature, issuer, audience and a per-login nonce) before trusting the email — so only a genuine response from your IdP can sign anyone in. You can disable SSO at any time, which immediately stops routing logins to your IdP (existing password logins are unaffected).
Getting started Reporting Report templates Filtering, dimensions & comparisons Sharing & delivering reports Metrics glossary AI visibility AI Shopping Visibility GEO Audit Signals & Automations AI traffic from GA4 Integrations Data, privacy & security The Crunch assistant Connect to Claude & ChatGPT (MCP) Account & billing Refer a friend FAQ