Single Sign-On (SSO) allows your organization to securely access Spruce using your existing identity provider, eliminating the need for teammates to manage separate Spruce passwords. Spruce currently supports Google Workspace SSO, with support for additional providers coming soon. SSO is only available on the Communicator Plan with the purchase of an add-on.
IN THIS ARTICLE
- Introduction to Single Sign-On (SSO)
- How to Enable SSO (Web Browser Only)
- Inviting Teammates to Spruce with SSO
- Removing Teammates from Spruce with SSO
- Disabling SSO for your Organization
- General SSO FAQs
Introduction to Single Sign-On (SSO)
Single Sign-On (SSO) helps organizations manage access more securely and efficiently by requiring that teammates sign in to Spruce with the same credentials as their organization’s SSO provider (ex. Google Workspace). SSO is only available on the Communicator Plan with the purchase of an add-on.
With SSO, teammates have one less password to manage, and organizations can apply their existing SSO provider’s security policies when accessing Spruce, such as including multi-factor authentication (MFA), sign-in and session requirements.
How to Enable SSO (Web Browser Only)
Step One: Purchase SSO Add-On
Single Sign-On (SSO) is available for customers on the Communicator plan with an add-on purchase of $300/month. Administrators must purchase the add-on before they can connect to an SSO provider in Spruce.
- Navigate to Settings > Organization Preferences > Single Sign-On (SSO) Authentication
- Click “Purchase SSO Add-On.” A dialog will appear on your screen.
- Check the checkbox to confirm you understand that your Spruce plan and monthly pricing will be adjusted.
- Click “Purchase Spruce Add-On” to complete your purchase. You will not be billed for the add-on until you enable SSO for your organization.
Step Two: Enable SSO for your organization
Once the add-on purchase is completed, administrators can enable Single Sign-On (SSO) for their organization using Spruce in a web browser by navigating to Settings > Organization Preferences > Single Sign-On (SSO) Authentication. Spruce supports Google Workspace SSO. SSO for Okta and Microsoft Entra ID are coming soon.
Inviting Teammates to Spruce with SSO
Administrators must manually invite teammates to Spruce.
To invite a teammate:
- Go to Settings > Teammates
- Select Invite Teammate
- Enter the teammate’s work email address. Phone numbers are not required for inviting teammates with SSO.
All teammate email addresses in Spruce must match your organization’s domain. Ex: If your organization uses "@exampleclinic.com", all teammates in Spruce must use an "@exampleclinic.com" email address.
Removing Teammates from Spruce with SSO
Removing Teammates from Google Workspace
Administrators must manually remove teammates from Spruce. Removing someone from Google Workspace does not remove them from Spruce. Learn more about removing teammates in Spruce.
If a teammate is removed from Google Workspace:
- They will be signed out of Spruce, and will not be able to sign in
- Their resources and assignments will not be automatically transferred to another teammate/team
Disabling SSO for your Organization
Admins can disable SSO for their Spruce organization in a web browser or the desktop app.
To disconnect SSO from your organization:
- Navigate to Settings > Organization Preferences > Single Sign-On (SSO)
- Click "Disconnect SSO". A dialog will appear on top of your screen.
- Review the content of this dialog, and then type “Disconnect” into the text box.
- Click the red Disconnect SSO button.
When SSO is disabled:
- All teammates will be signed out of Spruce immediately
- Teammates will no longer sign in through your SSO provider (Google Workspace, Okta, etc.)
- Your organization will return to email and password login with email two-factor authentication enabled
- All teammates will need to reset their password before signing in again
- Any future SSO add-on charges will be removed from your Spruce subscription, if applicable.
General SSO FAQs
See here for Google Workspace FAQs
Does Spruce support both SSO and email/password login?
No, organizations must choose either SSO or email/password login with two-factor authentication. All teammates must log in using the same method.
Is SSO included with my Spruce plan?
SSO is not included with the Basic or Communicator plans. It is available as a paid add-on for organizations on the Communicator plan.
How much does SSO cost?
SSO is available as a $300/month add-on for organizations on the Communicator plan. Organization administrators can purchase the add-on for a flat monthly fee. You will not be billed for the add-on until your organization has enabled SSO.
How will this appear on my Spruce bill?
The SSO add-on will appear as a separate line-item charge on your Spruce bill.
Navigate to Settings > Billing on a desktop computer, and then scroll down to the Invoices section. Click “View Invoices” to view and download your recent invoices.
Can I remove the add-on charge for SSO?
If you’d like to remove the add-on charge, you must disable SSO for your entire organization. When SSO is disabled, the add-on charge will automatically be removed from your next monthly bill.
Can teammates edit their email or password in Spruce when SSO is enabled?
No, this information is managed by your SSO provider.
Can patients use SSO?
No, Spruce does not currently support Single Sign-On for patient accounts.
How do my identity provider’s MFA and access policies work with SSO?
When you sign in to Spruce using SSO, you’re redirected to your identity provider to authenticate. Any MFA or access policies configured by your identity provider are enforced during that authentication process.
After authentication is complete, Spruce manages your active Spruce session separately. You won’t be prompted to authenticate with your identity provider again until your Spruce session expires or is revoked, or your identity provider revokes access.
Will enabling SSO for my organization affect incoming calls?
When SSO is enabled, teammates are logged out of Spruce and must sign back in using SSO. If a teammate is on an active call, they can complete the call before being logged out.
While teammates are logged out, they cannot receive new calls. Any unanswered calls will follow your organization’s usual call handling, such as going to voicemail. The transition should only cause a brief interruption.
How can I get help if I have trouble signing in with SSO?
If you can log in to Spruce, contact the Spruce Support team. If you’re unable to sign in, email support@sprucehealth.com for assistance.
What happens if I disable SSO for my organization?
When SSO is disabled, all teammates are immediately logged out of Spruce and can no longer sign in using SSO. Spruce will automatically email teammates with instructions for resetting their password.
- If a teammate's account existed before SSO was enabled: they can log in using their current email address and their previous Spruce password. They can also choose to reset their password.
- If a teammate's account was created after SSO was enabled: they will first need to reset their password in Spruce. They can then log into Spruce using their current email address and the new password.
What happens if I downgrade my Spruce account to the Basic Plan when SSO is enabled?
If SSO is enabled for your organization and you downgrade to the Basic Plan:
- All teammates will be signed out of Spruce immediately
- Teammates will no longer sign in with your SSO provider
- Your organization will return to email and password login with email two-factor authentication enabled
- Any future SSO add-on charges will be removed from your Spruce subscription, if applicable.
All teammates will need to reset their password before signing in again.