SSO & Authentication

Configure authentication providers including OAuth, SSO, and team invitations.

Authentication methods

Moneat supports multiple authentication methods:

  • Email & Password - Standard email-based authentication with email verification
  • GitHub OAuth - Sign in with your GitHub account
  • Apple Sign In - Sign in with your Apple ID
  • SSO - Enterprise single sign-on for organizations

GitHub OAuth

GitHub OAuth lets your team sign in using their GitHub accounts. This is the easiest way to get started if your team already uses GitHub.

  1. 1
    Click "Sign in with GitHub"
    On the login or signup page, click the GitHub button.
  2. 2
    Authorize Moneat
    You'll be redirected to GitHub to authorize the Moneat application. Review the permissions and click "Authorize".
  3. 3
    Complete onboarding
    If this is your first time, you'll be guided through creating your organization and first service.

Apple sign-in

Apple Sign In is available on both the web dashboard and mobile app. It provides a privacy-focused authentication option with support for hidden email relay.

Enterprise SSO

How SSO works

SSO allows your organization to use your existing identity provider (IdP) to authenticate users into Moneat. Users sign in through your company's SSO portal and are automatically provisioned in Moneat.

OIDC SSO

OIDC (OpenID Connect) SSO is available to all self-hosted deployments with no license required. It works with any standard OIDC provider including Authentik, Authelia, Keycloak, Okta, Azure AD, Auth0, and others.

For SaaS customers, OIDC SSO is available on the Team and Business plan tiers.

SAML SSO

SAML 2.0 SSO requires an enterprise license for self-hosted deployments, or a Team/Business plan for SaaS customers.

SSO enforcement (require SSO)

The "Require SSO" option blocks password login for all users in your organization, requiring authentication through your identity provider. This feature requires an enterprise license for self-hosted deployments, or a Team/Business plan for SaaS customers.

SSO Availability

OIDC SSO is available on all self-hosted deployments. SAML SSO and SSO enforcement require an enterprise license or Team/Business plan. Contact support if you need help configuring SSO for your organization.

SSO login flow

  1. 1
    Enter your email
    On the login page, click "Sign in with SSO" and enter your work email address.
  2. 2
    Redirect to your IdP
    Moneat looks up your organization's SSO configuration and redirects you to your identity provider.
  3. 3
    Authenticate
    Sign in with your company credentials through your IdP.
  4. 4
    Return to Moneat
    After successful authentication, you're redirected back to Moneat and logged in automatically.

Team invitations

Inviting members

Invite team members from Settings → Organization → Members. You can invite individually or in bulk using email addresses.

  • Enter the email address(es) of the people you want to invite
  • Select their role (Member or Admin)
  • They'll receive an email invitation with a link to join your organization

Managing members

Organization admins can manage team members from the Members settings:

  • Change roles - Promote or demote members between Member and Admin roles
  • Remove members - Remove a team member from your organization
  • Resend invitations - Resend pending invitation emails
  • Revoke invitations - Cancel pending invitations

Email verification

When signing up with email and password, users must verify their email address before accessing the dashboard. A verification link is sent to the provided email. If it doesn't arrive, you can request a new verification email from the verification page.