Skip to content

Sign-in and SSO

Create an account with your email address and a password of at least 8 characters. We email you an 8-digit code to confirm the address before your first sign-in. Forgot your password? Choose Forgot password? on the sign-in screen and we’ll email you a code to set a new one. Setting a new password signs out your other sessions.

Invitations are tied to an email address, so a teammate you invite must sign in with that address to join.

Where the sign-in screen shows Continue with Google or Continue with GitHub, you can sign in with those instead. A sign-in joins your existing account only when the provider confirms the email address.

If a provider doesn’t confirm it, your Account page shows the address as Not confirmed. Choose Send confirmation code there and enter the 8-digit code we email you. Accepting an invitation needs a confirmed address.

On the Enterprise plan, your people can sign in through your company’s identity provider. We set up company sign-in with you: Yokka connects one OpenID Connect identity provider, and SAML providers connect through an OIDC broker such as WorkOS. The sign-in screen shows one button for it, Continue with SSO or the name we give it.

To set it up, email support@yokka.ai with your workspace name and identity provider. We’ll send you what to register on your side and turn it on. Then verify your domain (below): SSO only vouches for addresses on domains your workspace has verified, and verified domains are what you can require SSO for.

Someone who signs in with SSO lands in their existing account when it has the same email address and that address was confirmed, or when your workspace has verified the address’s domain. In that second case any password on the account is removed and its other sessions are signed out. That way an account someone else created with a colleague’s address can’t be used to get in.

Admins prove the company owns its email domain under Workspace settings → Security → Domains and single sign-on:

  1. Enter the domain, like acme.com, and choose Add domain. Public mail providers such as gmail.com can’t be claimed.
  2. Add the TXT record it shows at your DNS provider.
  3. Choose Check DNS. DNS changes can take a few minutes to appear.

A domain can be verified by one workspace only.

Keep the TXT record in place. We check it again every day, and if it’s missing 3 days in a row the domain goes back to unverified, which also turns its auto-join off. Adding the record back and checking again verifies it again.

Once a domain is verified, turn on auto-join for it and choose the role people join with: member or viewer. Anyone who signs in with a confirmed address on that domain then joins your workspace with that role, and lands there instead of in a new workspace of their own. You can change their role afterwards.

Auto-join needs a free seat for that role; without one, people carry on without joining. Someone who left the workspace or was removed isn’t added back.

Turn on Require SSO for verified domains and people with an address on those domains can only sign in through SSO:

  • password sign-in, sign-up and password reset are refused for them,
  • other sign-in providers are refused for them,
  • everyone on those domains is signed out once, so their next sign-in goes through SSO.

To make sure nobody gets locked out, you can only turn it on after SSO is set up for your workspace, a domain is verified, and you have signed in with SSO yourself. Removing the last verified domain, or its going back to unverified, turns the requirement off.