Steps
These steps take a fresh install to single sign-on through your own identity provider. They apply to Helm, ArgoCD and Docker Compose installs alike.- Install LangWatch. No email provider is needed for these steps.
- Create the first account. Open LangWatch and sign up with an email and a password. Do not use a passkey, since step 5 links single sign-on to the password account. The first account is an ordinary organization administrator. It has no rights over the whole installation: the operator pages (
/ops) open only for the addresses inADMIN_EMAILS. Once another administrator exists, you can change this account’s role or remove it. - Add the license. Open Settings > License. Enter the activation code LangWatch sent you, which needs outbound HTTPS to
connect.langwatch.ai(see Connect). On an install without that access, paste or upload the license key instead (see Editions and licensing). Single sign-on turns on once the license is active, with no restart. - Connect your identity provider. Open Settings > Authentication > Identity provider and follow the setup:
- Register the connection with the issuer, client id and client secret from your identity provider, or with its SAML metadata.
- Copy the redirect URI the page shows into your identity provider. It has the form
https://<your LangWatch host>/api/auth/sso/callback/<connection id>. In Microsoft Entra ID, add it under the Web platform. - Add your domain.
- Run the test sign-in.
- Name an administrator who can still get in if the identity provider is unavailable.
- Choose who the connection lets in.
- Select Go live.
- Sign in through single sign-on. The administrator’s password account links to the identity provider on its first single sign-on sign-in, which is the test sign-in in step 4. You keep the same account, organization and projects.