Skip to main content
Single sign-on lets people in your organization sign in to Real-Time LCA with the identity provider (IdP) you already use — no separate Real-Time LCA password to set, share, or reset. SSO is set up per organization on request. An IT administrator asks for it by emailing support@realtimelca.com, and we configure the connection together with you.

Supported protocols

  • OpenID Connect (OIDC)
  • SAML 2.0
Most modern IdPs — Entra ID (Azure AD), Okta, Google Workspace, Ping, and others — support at least one of these.
This is different from the Microsoft button on the sign-in and activation screens. That option links a single user to their own Microsoft account. SSO connects your organization’s IdP, so everyone on your email domain signs in through it. See Activate your account.

How users get access

Users are provisioned automatically the first time they sign in through your identity provider — no activation email, and no need to create each user in Real-Time LCA up front. Anyone your IdP lets through on a claimed domain gets a Real-Time LCA user in your organization on first sign-in.
Being provisioned puts someone in your organization; it does not give them a project. Project access is still granted separately under Settings → Members.
Control who can reach Real-Time LCA the same way you control your other applications — by assigning the app registration to the right users or groups in your IdP.

Before you request SSO

Have these in place on your side:
1

An app registration in your IdP

Create the application (OIDC or SAML 2.0) that will represent Real-Time LCA in your IdP.
2

Permission to add a redirect URI

Whoever sets this up needs to be able to add the redirect URI we give you to that app registration.
3

The email claim in the token

Real-Time LCA identifies users by email, so the token must carry an email claim.
4

Control of the email domain you want to claim

You can only claim a domain you own, and ownership has to be verified before the connection goes live.
5

A named admin for the connection

One person on your side owns the connection over time and is our point of contact for changes to it.

Entra ID: add the email claim explicitly

In Entra ID the email claim is often missing by default. Two things to check:
  • Add email as a claim under the app registration’s Token configuration.
  • Make sure each user’s mail attribute is populated in the directory. If it is empty, no email claim is issued for that user and they cannot be matched to a Real-Time LCA user.
Users whose token arrives without an email claim will not be able to sign in. Check this before rolling SSO out to everyone.

How to request it

Email support@realtimelca.com from an IT administrator account and include:
  • Your organization name in Real-Time LCA
  • Which protocol you want to use — OIDC or SAML 2.0
  • The email domain (or domains) you want to claim
  • The named admin who will own the connection
We come back to you with the redirect URI to add to your app registration and the details we need from your side, verify the domain, and test the connection before it is switched on.

Next steps

Activate your account

How individual users activate and sign in today.

Account and user settings

Profile, workspace users, and organizations.