For Florida law firms
Single sign-on for a firm: its own identity provider, its own domain, just-in-time membership
firm lane · Deterministic — no model call
Current availability
Owner-gatedWaiting on the platform owner: SAML 2.0 turned on for the Supabase project, then SSO_SAML_ENABLED=1 on the deployment, and each firm's provider registered with `supabase sso add` (owner steps, docs/auth/SSO-OWNER-GUIDE.md); Supabase Pro includes 50 single sign-on users a month, then $0.015 each.
- Where it lives
- Firm settings (/firms/manage → Single sign-on) · Firm sign-in (/firms/login → Sign in with your firm's single sign-on) · the platform's Single sign-on requests (/admin/sso) · /api/firm/sso · /api/auth/sso · /api/admin/sso
- What unlocks it
- a firm's administrator asks; the platform's administrator activates after the DNS proof; people at the firm's domain sign in through the firm's provider
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- Owner-gatedA firm's administrator asks for single sign-on for the firm's own email domain — never a public mail provider's, never a domain another firm holds — and is given a DNS proof to publish (a TXT record at _estatedraftfl-sso.<domain>), with the details its identity provider needs (entity ID, reply URL, metadata, email as the name ID).
- Owner-gatedThe platform's administrator registers the firm's provider on the Auth server, and activates the request only after reading the DNS proof; the activation is on the audit record.
- Owner-gatedA person who signs in through the firm's provider with an address at that domain joins that firm — as a paralegal (the firm's administrator names attorneys) — and no other: the platform reads the provider from the person's own identity record, never from the request.
- Owner-gatedA person the firm's deprovisioning door removed cannot rejoin through single sign-on until the firm invites them again.
- Owner-gatedSign-in starts on the firm's own site; from anywhere else the person is sent there first.
- Owner-gatedThe firm's administrator turns a connection off with a reason; nobody joins through it again, and members keep the access they have.
Limits
- SAML 2.0 only, started from the platform's sign-in (an identity provider's own launcher links to the firm's sign-in page); no SCIM — leaving is the firm's deprovisioning door.
- The platform's own second factor still applies to a firm's console: single sign-on proves who the person is, the platform's factor guards the firm's work.
- A single sign-on account is a separate account from an email-link account with the same address; the firm's administrator gives it the role it needs.
- Single sign-on users beyond the 50 a month Supabase Pro includes are billed by Supabase at $0.015 each.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| forbidden | 403 | Only the firm's administrator asks for or turns off single sign-on; only the platform's administrator activates it. |
| invalid | 400 | The domain or the metadata address could not be read (a domain like yourfirm.com; an https metadata address). |
| public-domain | 400 | A public mail provider's domain cannot sign a firm in. |
| domain-taken | 409 | Another firm has asked for that domain. |
| dns-not-found | 409 | The firm's DNS proof is not readable yet — the record to publish is named. |
| provider-taken | 409 | That provider already signs another firm in. |
| not-configured | 404 | Single sign-on isn't set up for that address's domain — the email link is the way in. |
| sso-departed | 403 | The person's access to the firm ended; the firm invites them again to let them back in. |
| unavailable | 503 | A read or the provider could not answer just now — nothing was changed. |
Evidence
- supabase/migrations/20261003220000_phase21_sso_deprovision.sql
- src/lib/sso.ts
- src/lib/sso-server.ts
- src/lib/sso.test.ts
- src/lib/phase21-sso-routes.test.ts
- src/app/api/auth/sso/route.ts
- src/app/api/firm/sso/route.ts
- src/app/api/admin/sso/route.ts
- src/app/auth/callback/route.ts
- src/components/FirmSsoPanel.tsx
- src/components/SsoSignIn.tsx
- docs/auth/SSO-OWNER-GUIDE.md
Last reviewed 2026-10-03