Hub documentation
Single Sign-On (SSO)
Single Sign-On (SSO)
This feature is part of the Team & Enterprise plans.
Hugging Face supports Single Sign-On (SSO) to let organizations manage user authentication through their own Identity Provider (IdP). Both SAML 2.0 and OpenID Connect (OIDC) protocols are supported.
There are two SSO models available, depending on your plan and needs. For a detailed comparison, see the SSO overview.
- Basic SSO — Available on Team & Enterprise plans. Adds an access-control layer on top of the standard Hugging Face login to secure your organization’s resources.
- Managed SSO — Available on the Enterprise Plus plan. Replaces the Hugging Face login entirely, giving your organization full control over user accounts and access. Requires setup with the Hugging Face team — contact us to get started.
Further reading
- User Management — Role mapping, resource group mapping, session timeout, and more
- Configuration Guides — Step-by-step setup instructions for Okta, Microsoft Entra ID, and Google Workspace
- User Provisioning (SCIM) — Automated user provisioning from your Identity Provider