SSO and MFA: frequently asked questions
Common questions about how SSO and MFA work on Kovira.
Is MFA included on the free tier?+
Yes - and it is mandatory, not optional. Every account on every Kovira plan, including the free tier, requires multi-factor authentication on sign-in. There is no plan upgrade required to turn on MFA, and there is no option to turn it off.
Why is MFA mandatory rather than optional?+
Because optional MFA is not really MFA. If a single account on a workspace can opt out, that account becomes the weakest link, and the workspace is only as secure as the loosest credential. We removed the choice deliberately - every account, every plan.
Which plans include SSO?+
All paid plans: Teams, Business, and MSP. Single sign-on uses SAML 2.0 so it works with Microsoft Entra ID, Okta, Google Workspace, OneLogin, JumpCloud, and any other identity provider that speaks SAML. The free tier uses email-and-password sign-in with mandatory MFA.
Why isn't SSO on the free tier as well?+
Honestly, because SSO meaningfully changes the integration burden on our side and we want the free tier to remain genuinely free without us having to claw it back somewhere. The free tier still has mandatory MFA on every account, so the security baseline is unchanged. SSO becomes available the moment you upgrade to any paid plan, starting at the lowest tier.
What's the deal with the so-called "SSO tax"?+
It's a pattern where SaaS vendors gate single sign-on behind their highest-tier (often "Enterprise") plan, frequently at a multiple of the price of the plan immediately below it. The result is that organisations have to choose between secure-by-design identity and a reasonable bill. We don't believe SSO should sit behind that wall, so we put it on the lowest paid tier.
What standards does Kovira use for SSO and MFA?+
SSO uses SAML 2.0, the industry standard for federated identity. MFA uses time-based one-time passwords (TOTP), compatible with any standard authenticator app such as Authy, Google Authenticator, 1Password, Microsoft Authenticator, or hardware tokens that emit TOTP codes.
Can I enforce SSO-only access for my workspace?+
On Teams, Business, and MSP plans, yes - workspace owners can require SSO for all members of a workspace, so individual accounts cannot fall back to email-and-password sign-in once SSO is configured for the organisation.
How do I add SSO to my Kovira workspace?+
Once you are on a paid plan, an Owner can configure SAML 2.0 SSO from workspace settings. We provide the standard SAML metadata (entity ID, ACS URL, certificate) and accept identity provider metadata back. The setup is the standard SAML round-trip; no professional services engagement required.