- Short answer
- Yes, but only on Shopify Plus: SAML for staff and your own OpenID Connect provider for customers on new customer accounts.
- Before requiring SAML
- It covers every account on your domain, store owner included; create a backup account off that domain first.
- Removing a leaver
- Removing someone from the Shopify app in your identity provider still leaves them up to 14 days of Shopify access.
- Customer identity providers
- Connect several if you like, but only one is active on your online store; sessions default to 90 days.
- Multipass
- Closed to new stores; Plus stores already using it keep it after upgrading to new customer accounts.
- Shopify ID
- Help Center calls it “single sign-on”, but it is one Shopify login, not your company’s identity provider.
Can your staff sign in to Shopify through Okta, OneLogin or Entra?
Yes, if your organization is on the Shopify Plus plan. Shopify makes SAML authentication available only to Plus organizations, and you add Shopify as an app in your identity provider. Shopify currently has configurations for Okta, OneLogin and Entra; with any other provider, you enter the configuration data by hand.
There are two gates, in order. First the plan: SAML sits in Users > Security among the Plus-only advanced security features, part of the organization layer described in our Shopify Plus guide. Then the domain: verifying it is also a Plus feature, and the SAML authentication settings unlock once its status is verified (you can start the configuration before that).
With the domain and a SAML configuration in place, Plus can add SCIM: your identity provider can create users, assign or update groups, and deactivate users in Shopify. Store owners and organization owners can't be removed that way; how SCIM provisioning works on Plus covers the rest.
What changes for your team once SAML is switched on?
Who has to sign in through your identity provider depends on the setting you pick: Required, Specific users or Off. Required is the one that bites, because Shopify scopes it by email domain rather than by your staff list:
The Required setting affects all users who have Shopify accounts associated with the email domain that you set, including the store owner and users outside the organization.
With Specific users, you choose people from the Users page, and everyone not set to require SAML keeps signing in with their regular credentials.
Sessions run long. On desktop, a SAML session lasts 14 days before people must log in again. Separately, someone you remove from the Shopify app in your identity provider can still access Shopify for up to 14 days.
So treat that removal as the start of offboarding, not the end, and work through the access-revocation steps in Shopify as well.
Can customers sign in to your store with single sign-on?
Yes, but only on Plus. In new customer accounts you can replace the default sign-in by connecting your own identity provider that is OpenID Connect compliant, such as Auth0 or Okta, and customers then sign in through it with single sign-on.
You can connect several providers, but only one is active on your online store at a time, and customer sessions are valid for 90 days by default. The provider must use email as the unique identifier, with email verification in its registration.
Multipass, which also requires Plus, is a different story:
Multipass is no longer available to new stores. Stores already using it keep access even after they upgrade to new customer accounts.
For a store with a third-party identity provider configured, Shopify's developer docs call the single sign-on redirect the recommended replacement for Multipass. The Multipass page adds that a store that downgrades off Plus loses Multipass on new customer accounts.
Shopify's own pages disagree on whether Multipass works on new customer accounts at all: the shopify.dev customer authentication overview says it doesn't and recommends that stores using it with classic customer accounts migrate to a third-party identity provider, while the Multipass page quoted above and the Help Center upgrade guide say the opposite for an existing Plus integration. If you are moving off legacy accounts, our customer accounts migration guide covers what else changes.
What can you use without Shopify Plus?
Sign-in security, social sign-in and App Store apps — not staff SAML or a customer identity provider, which Shopify makes Plus-only. No Help Center page we read on October 8, 2026 (SAML, SCIM, domain verification, advanced security) describes SAML or SCIM for organizations outside Plus. What you can use:
- Shopify ID. The Help Center describes it as "also known as single login, single sign-on, or SSO", but it is your email address and a password for Shopify, not a link to your company's identity provider.
- Login services. You can connect your own Shopify account to an external login service such as Apple, Google or WhatsApp, if your region and your account with that service are eligible; Facebook can no longer be added as a new login service.
- Passkeys and two-step authentication as secure sign-in methods on each account. When two-step authentication is required has its own answer.
- Customer sign-in. Customers sign in passwordless by default, and you can add Google and Facebook sign-in from your Customer accounts settings. Shopify's sign-in options page also lists Apple and Shop, while the social sign-in page names only Google and Facebook (both read October 8, 2026); the providers your Customer accounts settings offer are the ones you can turn on.
- Apps. The Shopify App Store carries miniOrange Single Sign On-SSO; check whether it signs in staff, customers or both before installing.
This page was written by AI. Separate AI agents that did not write it check its figures and claims against official sources and test its links and interactive tools. A human editor sets the site's editorial direction, topics and rules and checks that pages are complete and display correctly, but does not check their facts or edit their text. Details may change — always confirm critical data at shopify.com.
Editorial Policy