AnchorMark
Identity

Single sign-on without the ticket queue.

WorkOS-powered SAML, OIDC, and SCIM. Add or revoke access from your identity provider and AnchorMark follows in seconds.

See pricing
Problem

Why this hurts today

Manually provisioning every reviewer at a 500-person company is a security incident waiting to happen. Tickets pile up at IT, deactivations get missed, and ex-employees keep access to projects long after their last day.

Solution

What AnchorMark does

Connect Okta, Azure AD, JumpCloud, or any SAML/OIDC IdP. SCIM keeps user and group state in sync; AnchorMark mirrors role assignments. Domain capture auto-claims new joiners from your verified domain, and every login and provisioning event is recorded in the audit log so security review is one export away.

Capabilities

What you get when you turn this on.

SAML 2.0 + OIDC

Connect any major IdP through WorkOS.

SCIM 2.0

Just-in-time and bulk user provisioning, group sync, deactivation.

Domain capture

Auto-claim users joining from your verified domain.

Audit trail

Every login and provisioning event recorded for compliance.

Group-to-role mapping

SCIM groups drive AnchorMark <a href="/features/user-groups">custom user groups</a> automatically.

Enforce SSO

Disable password login on a workspace so identity is the only way in.

Frequently asked questions

Which plan includes SSO and SCIM?
Both are part of the Enterprise plan and can be added a-la-carte to Agency by request. Talk to sales for sizing on multi-workspace deployments.
Do you support SCIM group-to-role mapping?
Yes — AnchorMark roles can be derived from SCIM groups so identity stays the source of truth. Add a person to a group in your IdP and they pick up the matching custom user group in AnchorMark within seconds.
Which identity providers are supported?
Okta, Azure AD, JumpCloud, Google Workspace, OneLogin, Ping, and any SAML 2.0 or OIDC provider through WorkOS. Custom IdPs are supported on Enterprise — contact sales with the protocol details.
Can I require SSO and disable password login?
Yes. Enterprise workspaces can enforce SSO so members must authenticate through the IdP. Magic-link guest reviewers can also be required to use SSO if you've connected one.
How fast does deactivation propagate?
SCIM deactivation suspends the user and terminates active sessions within seconds. Every termination is recorded in the audit log for compliance review.
Do you charge per SSO connection?
No — SSO and SCIM are included with Enterprise without per-connection fees, regardless of how many subsidiaries or partner orgs you connect.

Ship faster with feedback that already has the receipts.

Start a 14-day trial of the Team plan — no credit card required.

Compare plans