Ecom Store Pro

Does Shopify support single sign-on (SSO)?

Published ·
At a glance
Short answer
Yes, but only on Shopify Plus: SAML for staff and your own OpenID Connect provider for customers on new customer accounts.
Before requiring SAML
It covers every account on your domain, store owner included; create a backup account off that domain first.
Removing a leaver
Removing someone from the Shopify app in your identity provider still leaves them up to 14 days of Shopify access.
Customer identity providers
Connect several if you like, but only one is active on your online store; sessions default to 90 days.
Multipass
Closed to new stores; Plus stores already using it keep it after upgrading to new customer accounts.
Shopify ID
Help Center calls it “single sign-on”, but it is one Shopify login, not your company’s identity provider.

Can your staff sign in to Shopify through Okta, OneLogin or Entra?

Yes, if your organization is on the Shopify Plus plan. Shopify makes SAML authentication available only to Plus organizations, and you add Shopify as an app in your identity provider. Shopify currently has configurations for Okta, OneLogin and Entra; with any other provider, you enter the configuration data by hand.

There are two gates, in order. First the plan: SAML sits in Users > Security among the Plus-only advanced security features, part of the organization layer described in our Shopify Plus guide. Then the domain: verifying it is also a Plus feature, and the SAML authentication settings unlock once its status is verified (you can start the configuration before that).

With the domain and a SAML configuration in place, Plus can add SCIM: your identity provider can create users, assign or update groups, and deactivate users in Shopify. Store owners and organization owners can't be removed that way; how SCIM provisioning works on Plus covers the rest.

What changes for your team once SAML is switched on?

Who has to sign in through your identity provider depends on the setting you pick: Required, Specific users or Off. Required is the one that bites, because Shopify scopes it by email domain rather than by your staff list:

The Required setting affects all users who have Shopify accounts associated with the email domain that you set, including the store owner and users outside the organization.
Shopify Help Center — SAML authentication ·

With Specific users, you choose people from the Users page, and everyone not set to require SAML keeps signing in with their regular credentials.

Create a backup account before you require SAML
Required covers the store owner too. In case of issues with your SAML integration or an interruption at your identity provider, Shopify recommends a backup account that isn't associated with the domain you use for SAML.

Sessions run long. On desktop, a SAML session lasts 14 days before people must log in again. Separately, someone you remove from the Shopify app in your identity provider can still access Shopify for up to 14 days.

So treat that removal as the start of offboarding, not the end, and work through the access-revocation steps in Shopify as well.

Can customers sign in to your store with single sign-on?

Yes, but only on Plus. In new customer accounts you can replace the default sign-in by connecting your own identity provider that is OpenID Connect compliant, such as Auth0 or Okta, and customers then sign in through it with single sign-on.

You can connect several providers, but only one is active on your online store at a time, and customer sessions are valid for 90 days by default. The provider must use email as the unique identifier, with email verification in its registration.

Multipass, which also requires Plus, is a different story:

Multipass is no longer available to new stores. Stores already using it keep access even after they upgrade to new customer accounts.
Shopify Developer Documentation — Multipass ·

For a store with a third-party identity provider configured, Shopify's developer docs call the single sign-on redirect the recommended replacement for Multipass. The Multipass page adds that a store that downgrades off Plus loses Multipass on new customer accounts.

Shopify's own pages disagree on whether Multipass works on new customer accounts at all: the shopify.dev customer authentication overview says it doesn't and recommends that stores using it with classic customer accounts migrate to a third-party identity provider, while the Multipass page quoted above and the Help Center upgrade guide say the opposite for an existing Plus integration. If you are moving off legacy accounts, our customer accounts migration guide covers what else changes.

What can you use without Shopify Plus?

Sign-in security, social sign-in and App Store apps — not staff SAML or a customer identity provider, which Shopify makes Plus-only. No Help Center page we read on October 8, 2026 (SAML, SCIM, domain verification, advanced security) describes SAML or SCIM for organizations outside Plus. What you can use:

  • Shopify ID. The Help Center describes it as "also known as single login, single sign-on, or SSO", but it is your email address and a password for Shopify, not a link to your company's identity provider.
  • Login services. You can connect your own Shopify account to an external login service such as Apple, Google or WhatsApp, if your region and your account with that service are eligible; Facebook can no longer be added as a new login service.
  • Passkeys and two-step authentication as secure sign-in methods on each account. When two-step authentication is required has its own answer.
  • Customer sign-in. Customers sign in passwordless by default, and you can add Google and Facebook sign-in from your Customer accounts settings. Shopify's sign-in options page also lists Apple and Shop, while the social sign-in page names only Google and Facebook (both read October 8, 2026); the providers your Customer accounts settings offer are the ones you can turn on.
  • Apps. The Shopify App Store carries miniOrange Single Sign On-SSO; check whether it signs in staff, customers or both before installing.
About This Article

This page was written by AI. Separate AI agents that did not write it check its figures and claims against official sources and test its links and interactive tools. A human editor sets the site's editorial direction, topics and rules and checks that pages are complete and display correctly, but does not check their facts or edit their text. Details may change — always confirm critical data at shopify.com.

Editorial Policy

Related questions

Plans & getting started
Does Shopify Plus support SCIM user provisioning?

Yes, for Plus organizations only — SCIM creates users, assigns groups and deactivates them; deletion depends on your identity provider.

Updated October 6, 2026

Admin, staff & security
How do you log out of all devices on Shopify?

Log out devices under Security > Devices; Log out all devices is offered when more than five recently logged in and signs you out too.

September 29, 2026

Products & inventory
Does a child product keep its own page after it is added to a Shopify Combined Listing?

Yes — on Plus and enterprise plans a child keeps its page and URL; no help page we read documents a status change for a child. Unlisted is manual.

Updated October 6, 2026

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.