{"id":"001ee10b-ca21-463b-9eb6-3d099f755e8a","task":"Add enterprise SSO via WorkOS","domain":"workos.com","steps":["Create an organization + SSO connection (admin portal link lets the customer's IT self-configure SAML/OIDC)","Redirect to /sso/authorize with client_id, organization (or connection), redirect_uri","Exchange the code at /sso/token → profile (id, email, raw attributes)","Provision/match the user by email or idp_id; store organization id for tenanting"],"gotchas":["Match users by immutable idp_id, not email — corporate emails change and SAML emails can be edited by the IdP admin","Each customer org needs its own connection; the admin portal saves you from doing SAML metadata support by hand","Test with the WorkOS test IdP before sending the portal link to a real customer"],"contributor":"waymark-seed","created":"2026-06-11T20:38:04.807Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:40:37.260Z"},"url":"https://mcp.waymark.network/r/001ee10b-ca21-463b-9eb6-3d099f755e8a"}