# Single Sign-On

> How SSO works on Road, and when to choose SAML or OIDC.

Single Sign-On (SSO) lets your users reach Road with the credentials they already have, rather than a separate Road login. Road supports two standards, **SAMLv2** and **OpenID Connect (OIDC)**, and which one fits depends on who is signing in.

## Two ways to use it

### Corporate directory, over SAML

For a company that manages its people in a corporate directory, Road connects to that identity provider (IdP) over SAMLv2. The **SAML configuration is applied to a single Account**, so everyone who authenticates through the corporate IdP belongs to that Account, and the company keeps provisioning, roles and access policy in its own directory.

### Customer identities and social login, over OIDC

For a business whose users authenticate against an external IdP (WSO2, Auth0, Azure AD B2C and the like), Road connects over OIDC, with **each Account mapping its own IdP login to a Road user**. OIDC also drives **social login**, so users can sign in with Google, Apple, Facebook or another OIDC provider instead of a Road password.

### Provisioning on first login

Both SAML and OIDC can create a user automatically the first time they sign in, so you do not have to provision everyone up front. It is off by default and enabled per configuration.

## Choosing between them

- **SAML** fits corporate identity: one corporate directory, one Account, access managed centrally by the customer's administrators.
- **OIDC** is the more flexible fit for customer-facing sign-in and social login, configured per Account.

Use SAML to let a company manage its employees' access to Road through its directory; use OIDC for external customers or social login. See [SAML](/docs/platform/account-management/single-sign-on/saml) and [OpenID Connect (OIDC)](/docs/platform/account-management/single-sign-on/openid-connect) to set each up.
