Skip to main content
GET
Check if email domain has SSO enabled

Query Parameters

email
string<email>
required

Response

SSO domain check result

Minimal, login-routing-only result: the two booleans the login screen needs. Intentionally omits internal identifiers (org_id, org_slug, SSO provider id) and the org / identity-provider display names, so this unauthenticated endpoint cannot be used to map an email domain to a named tenant or its IdP. Throttled per IP (10/min) independently of the shared auth bucket.

sso_enabled
boolean
enforced
boolean

Whether password login is disabled for this domain.