Skip to contentSaltar al contenidoAle nan kontni anПерейти к содержимомуדלג לתוכן
EstateDraftFL

For Florida law firms

Single sign-on for a firm: its own identity provider, its own domain, just-in-time membership

firm lane · Deterministic — no model call

Current availability

Owner-gatedWaiting on the platform owner: SAML 2.0 turned on for the Supabase project, then SSO_SAML_ENABLED=1 on the deployment, and each firm's provider registered with `supabase sso add` (owner steps, docs/auth/SSO-OWNER-GUIDE.md); Supabase Pro includes 50 single sign-on users a month, then $0.015 each.

Where it lives
Firm settings (/firms/manage → Single sign-on) · Firm sign-in (/firms/login → Sign in with your firm's single sign-on) · the platform's Single sign-on requests (/admin/sso) · /api/firm/sso · /api/auth/sso · /api/admin/sso
What unlocks it
a firm's administrator asks; the platform's administrator activates after the DNS proof; people at the firm's domain sign in through the firm's provider

Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.

Capabilities

  • Owner-gatedA firm's administrator asks for single sign-on for the firm's own email domain — never a public mail provider's, never a domain another firm holds — and is given a DNS proof to publish (a TXT record at _estatedraftfl-sso.<domain>), with the details its identity provider needs (entity ID, reply URL, metadata, email as the name ID).
  • Owner-gatedThe platform's administrator registers the firm's provider on the Auth server, and activates the request only after reading the DNS proof; the activation is on the audit record.
  • Owner-gatedA person who signs in through the firm's provider with an address at that domain joins that firm — as a paralegal (the firm's administrator names attorneys) — and no other: the platform reads the provider from the person's own identity record, never from the request.
  • Owner-gatedA person the firm's deprovisioning door removed cannot rejoin through single sign-on until the firm invites them again.
  • Owner-gatedSign-in starts on the firm's own site; from anywhere else the person is sent there first.
  • Owner-gatedThe firm's administrator turns a connection off with a reason; nobody joins through it again, and members keep the access they have.

Limits

  • SAML 2.0 only, started from the platform's sign-in (an identity provider's own launcher links to the firm's sign-in page); no SCIM — leaving is the firm's deprovisioning door.
  • The platform's own second factor still applies to a firm's console: single sign-on proves who the person is, the platform's factor guards the firm's work.
  • A single sign-on account is a separate account from an email-link account with the same address; the firm's administrator gives it the role it needs.
  • Single sign-on users beyond the 50 a month Supabase Pro includes are billed by Supabase at $0.015 each.

What EstateDraftFL refuses

Reason codeHTTPWhat it means
forbidden403Only the firm's administrator asks for or turns off single sign-on; only the platform's administrator activates it.
invalid400The domain or the metadata address could not be read (a domain like yourfirm.com; an https metadata address).
public-domain400A public mail provider's domain cannot sign a firm in.
domain-taken409Another firm has asked for that domain.
dns-not-found409The firm's DNS proof is not readable yet — the record to publish is named.
provider-taken409That provider already signs another firm in.
not-configured404Single sign-on isn't set up for that address's domain — the email link is the way in.
sso-departed403The person's access to the firm ended; the firm invites them again to let them back in.
unavailable503A read or the provider could not answer just now — nothing was changed.

Evidence

  • supabase/migrations/20261003220000_phase21_sso_deprovision.sql
  • src/lib/sso.ts
  • src/lib/sso-server.ts
  • src/lib/sso.test.ts
  • src/lib/phase21-sso-routes.test.ts
  • src/app/api/auth/sso/route.ts
  • src/app/api/firm/sso/route.ts
  • src/app/api/admin/sso/route.ts
  • src/app/auth/callback/route.ts
  • src/components/FirmSsoPanel.tsx
  • src/components/SsoSignIn.tsx
  • docs/auth/SSO-OWNER-GUIDE.md

Last reviewed 2026-10-03

← All surfaces