Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
In this article, you learn how to integrate Lovable with Microsoft Entra ID by using OpenID Connect (OIDC). When you integrate Lovable with Microsoft Entra ID, you can:
- Use Microsoft Entra ID to control who can access Lovable.
- Enable your users to sign in to Lovable with their Microsoft Entra accounts.
- Manage access to Lovable in one central location.
Lovable supports OIDC-based workspace single sign-on (SSO) for Business and Enterprise workspaces. Lovable supports service provider (SP)-initiated sign-on only. Users must start sign-in from Lovable.
Prerequisites
To get started, you need the following items:
- A Microsoft Entra subscription. If you don't have a subscription, you can get a free account.
- A Lovable Business or Enterprise workspace.
- Owner or administrator permissions in the Lovable workspace.
- A verified domain in Lovable.
Add Lovable (OIDC) from the gallery
To configure the integration of Lovable into Microsoft Entra ID, you need to add Lovable from the gallery to your list of managed SaaS apps.
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > New application.
In the Add from the gallery section, enter Lovable in the search box.
Select Lovable in the results panel and then add the app. Wait a few seconds while the app is added to your tenant.
Configure Microsoft Entra SSO
Follow these steps to enable Microsoft Entra SSO in the Microsoft Entra admin center.
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > Lovable > Single sign-on.
Perform the following steps in the below section:
Navigate to Authentication on the left menu and perform the following steps:
Navigate to API permissions on the left menu.
Verify that the Microsoft Graph delegated permissions required by Lovable are configured:
emailopenidprofile
Select Grant admin consent for the configured permissions.
Navigate to Certificates & secrets on the left menu and perform the following steps:
Go to the Client secrets tab and select New client secret.
Enter a description, select an expiration period, and then select Add.
Copy the client secret Value. You use this value later in the Lovable configuration.
Important
Copy the client secret value immediately. It isn't shown again after you leave the page.
Create a Microsoft Entra test user
In this section, you create a test user called B.Simon.
Sign in to the Microsoft Entra admin center as at least a User Administrator.
Browse to Entra ID > Users.
Select New user > Create new user.
In the User properties, follow these steps:
In the Display name field, enter
B.Simon.In the User principal name field, enter the username@companydomain.extension. For example,
B.Simon@contoso.com.Select the Show password check box, and then write down the value that's displayed in the Password box.
Select Review + create.
Select Create.
Assign the Microsoft Entra test user
In this section, you enable B.Simon to use single sign-on by granting access to Lovable.
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps.
In the applications list, select Lovable.
In the app's overview page, select Users and groups.
Select Add user/group, and then select Users and groups.
In the Users and groups dialog, select B.Simon from the users list, and then select Select.
In the Add Assignment dialog, select Assign.
Configure Lovable OIDC SSO
Below are the configuration steps to complete the OIDC SSO setup in Lovable:
Sign in to Lovable as a workspace owner or administrator.
Go to your workspace Settings. In the sidebar, under Members & access, select Identity.
If your domain isn't verified yet, verify it first:
In the Verified domains section, select Add domain.
In the Domain box, enter your domain (for example,
contoso.com).Add the TXT record shown on the page to your DNS provider. DNS changes can take from a few minutes up to 72 hours to propagate.
Select Verify domain, and after the domain is verified, select Continue.
In the SSO providers section, select Add provider.

On the Choose SSO Protocol step, select Configure OIDC under OpenID Connect (OIDC).

Lovable shows preparation steps that summarize the identity provider setup you already completed in Microsoft Entra ID (application settings, redirect URI, and OAuth scopes). Select Next to move through them, and then select I've Configured My IdP.
On the Configure OIDC Provider step, perform the following steps:

In OIDC Issuer URL / Discovery Endpoint, enter the following URL. Replace
{TENANT_ID}with the Directory (tenant) ID value that you copied from Microsoft Entra ID.https://login.microsoftonline.com/{TENANT_ID}/v2.0In OAuth Client ID / Application ID, paste the Application (client) ID value that you copied from Microsoft Entra ID.
In OAuth Client Secret, paste the client secret value that you copied from Microsoft Entra ID.
In Display Name, enter the name that users see during authentication.
In Verified domain, select the verified domain to use for SSO. The SSO login URL is based on this domain.
Optionally, in Login URL suffix, enter a suffix for the SSO login identifier. The resulting SSO login URL is shown below the field; users can use this URL to sign in directly with SSO.
Select Test configuration to validate the OIDC configuration.
On the Test results step, review the validation results, and then select Configure provider.
Review the confirmation page, and then select Confirm & enable SSO to finish the Lovable OIDC SSO configuration.
The provider now appears in the SSO providers section together with its SSO login URL, which you can copy and share with your users.
Note
Wait 6 hours and test SSO login before enforcing SSO for the workspace. Lovable disables the Enforce SSO toggle during this period for newly created providers.
Test SSO
Lovable supports SP-initiated sign-on only. IdP-initiated sign-on from a Microsoft Entra application tile isn't supported.
To test SSO, go to Lovable and start the SSO sign-in flow. If you configured an SSO login identifier in Lovable, users can also start sign-in by using the following URL:
https://lovable.dev/sso-login/{tenantId}
Replace {tenantId} with the SSO login identifier configured in Lovable.
Additional Lovable SSO settings
After the OIDC provider is configured, a Lovable workspace owner or administrator can enforce SSO for the workspace in Settings > Workspace > Identity. When SSO is enforced, workspace members must authenticate with SSO.
Lovable supports just-in-time (JIT) provisioning through SSO. User accounts are created automatically the first time users sign in with SSO and are added to the company workspace. Lovable also supports SCIM provisioning on the Enterprise plan.



