diff --git a/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts b/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts
index f367d6aad97..528afb8db03 100644
--- a/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts
+++ b/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts
@@ -308,6 +308,17 @@ export const auth = {
url: '/guides/auth/social-login',
items: [...SocialLoginItems],
},
+ {
+ name: 'Enterprise SSO',
+ url: '/guides/auth/enterprise-sso',
+ items: [
+ {
+ name: 'SAML 2.0 (Beta)',
+ url: '/guides/auth/sso/auth-sso-saml',
+ items: [],
+ },
+ ],
+ },
{ name: 'Email Templates', url: '/guides/auth/auth-email-templates', items: [] },
],
},
diff --git a/apps/docs/pages/guides/auth/enterprise-sso.mdx b/apps/docs/pages/guides/auth/enterprise-sso.mdx
new file mode 100644
index 00000000000..fbfb7b73915
--- /dev/null
+++ b/apps/docs/pages/guides/auth/enterprise-sso.mdx
@@ -0,0 +1,14 @@
+import Layout from '~/layouts/DefaultGuideLayout'
+
+export const meta = {
+ title: 'Enterprise SSO',
+ description: 'Learn about Single Sign-On support in Supabase Auth for enterprise applications',
+}
+
+Supabase Auth supports building enterprise applications that require Single Sign-On (SSO) authentication. At this time only [SSO with SAML 2.0](/guides/auth/sso/auth-sso-saml) is supported in an early beta.
+
+If you are interested in using SAML 2.0 SSO with your Supabase project, please [open a new support ticket](https://app.supabase.com/support/new).
+
+export const Page = ({ children }) =>
+
+export default Page
diff --git a/apps/docs/pages/guides/auth/sso/auth-sso-saml.mdx b/apps/docs/pages/guides/auth/sso/auth-sso-saml.mdx
new file mode 100644
index 00000000000..42c00314a61
--- /dev/null
+++ b/apps/docs/pages/guides/auth/sso/auth-sso-saml.mdx
@@ -0,0 +1,316 @@
+import Layout from '~/layouts/DefaultGuideLayout'
+
+export const meta = {
+ id: 'auth-sso-saml',
+ title: 'Single Sign-On with SAML 2.0',
+ description: 'Use Single Sign-On (SSO) authentication with SAML 2.0',
+ video: 'https://www.youtube.com/v/em1cpOAXknM',
+}
+
+Supabase Auth supports enterprise-level Single Sign-On (SSO) for any Provides compatible with the using the SAML 2.0 protocol.
+
+
+This is an early beta release of these APIs. CLI and Dashboard support for SSO is under development.
+
+If you are comfortable using these APIs and would like to try out SSO with SAML 2.0 for your project, please [open a support ticket](https://app.supabase.com/support/new).
+
+These APIs are not expected to change before the feature is generally available, but we do reserve the right to modify them. Projects in the Beta will be notified of any changes.
+
+
+
+## Terminology
+
+The number of SAML and SSO acronyms can often overwhelming. Here's a glossary which you can refer back to at any time:
+
+- **Identity Provider**, **IdP**, or **IDP**
+ This is software that manages user accounts at a company or organization. It can verify the identity of a user and exchange that information with your Supabase project. Commonly used identity providers are: Microsoft Active Directory (Azure AD, Microsoft Entra), Okta, Google Workspaces (GSuite), PingIdentity, OneLogin, and many others.
+- **Service Provider**, **SP**
+ This is the software that is asking for user information from an identity provider. In Supabase, this is your project's Auth server.
+- **Assertion**
+ An assertion is a statement issued by an identity provider that contains information about a user.
+- **EntityID**
+ A globally unique ID (usually a URL) that identifies an Identity Provider or Service Provider across the world.
+- **NameID**
+ A unique ID (usually an email address) that identifies a user at an Identity Provider.
+- **Metadata**
+ An XML document that describes the features and configuration of an Identity Provider or Service Provider. It can be as a standalone document or as a URL. Usually (but not always) the `EntityID` is the URL at which you can access the Metadata.
+- **Certificate**
+ Supabase Auth (the Service Provider) trusts assertions from an Identity Provider based on the signature attached to the assertion. The signature is verified according to the certificate present in the Metadata.
+- **Assertion Consumer Service (ACS) URL**
+ This is one of the most important SAML URLs. It is the URL where Supabase Auth will accept assertions from an identity provider. Basically, once the identity provider verifies the user's identity it will redirect to this URL and the redirect request will contain the assertion.
+- **Binding (Redirect, POST, or Artifact)**
+ This is a description of the way an identity provider communicates with Supabase Auth. When using the Redirect binding, the communication occurs using HTTP 301 redirects. When it's `POST`, it's using `POST` requests sent with `