Overview - ION Manual

Documentation Index

Fetch the complete documentation index at: /llms.txt

Use this file to discover all available pages before exploring further.

ION identifies every user by their company email address. When someone signs in, ION looks at the email’s domain to decide what happens next: if the domain has an SSO connection, ION redirects to your identity provider to authenticate; otherwise the user enters an ION password. Everything you configure on the Settings > Organization > Authentication page shapes that flow: which domains belong to your organization, whether SSO is on, whether MFA is required, and what the sign-in page looks like.

Two ways to sign in

The two coexist per domain, not per user: once SSO is active for a verified domain, users on that domain are routed to the IdP.

Domains

A claimed, verified domain tells ION that email addresses on that domain belong to your organization. Verification works by DNS: ION gives you a TXT record to publish, then confirms you own the domain. A verified domain acts as an allowlist that associates matching users with your organization at sign-up, and it’s the prerequisite for SSO. See Manage domains.