# Single sign-on

## Sign in to Tomba with Salesforce

Salesforce can be the SAML identity provider of your Tomba workspace, using Tomba's standard SSO setup
(Enterprise plan):

1. In Salesforce **Setup › Identity Provider**, click **Enable Identity Provider**.
2. Create a connected app for Tomba with SAML enabled, using the **Entity ID** and **ACS URL** shown on
   [app.tomba.io › Settings › Workspace › SSO](https://app.tomba.io/settings/workspace/sso). Send the user's email
   as the subject (Name ID format *emailAddress*), and give your Tomba users access to the app.
3. Back in **Setup › Identity Provider**, click **Download Metadata**.
4. On app.tomba.io › Settings › Workspace › SSO, click **Configure SAML SSO** and upload that file.

Test it from a private window with **Sign in with SSO**, then choose how members sign in (*SSO optional* or
*SSO required*). Invite teammates and manage members on app.tomba.io as usual.
