← Back to home

Product

Single sign-on for your MSP team

What protocol does single sign-on use?
OpenID Connect. The providers with automatic discovery are Microsoft Entra ID, Okta and Google Workspace.
How do I prove the domain is mine?
By publishing a TXT record in the domain's DNS with the value the panel gives you. KairosLink verifies it and re-verifies it every 7 days: if the record disappears, the domain stops allowing sign-ins.
Can I use a Gmail or Outlook account?
Not to claim a domain. Public email domains are on a list that cannot be claimed, because whoever claimed one would take the sign-ins of every user on that domain.
If someone signs in with the identity provider, are they already inside the panel?
No. Every new federated access lands in an approval queue and is enabled by hand by someone with the user management permission. The provider proves identity; your MSP grants access.
Does KairosLink honor my provider's second factor?
Yes. It reads from the token which method the person authenticated with, and only takes a closed list of values as a second factor: authenticator app, hardware key, biometrics, SMS and each provider's variants. A password alone never counts.
What happens if the identity provider goes down?
The sign-in flow lives for 10 minutes and the timeouts against the provider are deliberately short, so a slow provider cannot leave the sign-in screen hanging.
Try KairosLink free for 14 days

All modules included. No credit card.