A domain is optional for SSO: a named SAML configuration can use its dedicated
sign-in URL without a linked domain. Verify a domain when you want
domain-based sign-in or enrollment. See SAML SSO
Setup.
Prerequisites
- An organization Owner or Admin role.
- Domain management enabled for your organization through its plan capabilities.
- Access to DNS settings for the domain you want to verify.
Add and Verify a Domain
1
Open Domains & Access
Open Domains & Access ↗ under your organization.
2
Add your domain
Click Add Domain, enter the email domain (for example,
acme.com), and submit it. Krea shows the DNS verification details. You can choose Verify Later and return to the pending domain from the domains table.3
Create the DNS record
Copy the TXT value exactly as shown and add it at your DNS provider.
For a subdomain, make sure the record resolves at that subdomain rather than at the parent domain.
4
Verify in Krea
Return to Krea and click Verify Domain. The domain remains Pending until the DNS check succeeds, then shows as Verified. If DNS has not propagated yet, wait and try again.
Newly verified organization domains start with capture Off. DNS
verification alone does not automatically enroll matching users. Review the
capture mode after verification.
Configure Domain Capture
In the domains table, use the verified domain’s Capture mode dropdown.
Domain capture governs organization membership. Access to individual workspaces is managed separately from Workspaces → Workspace Access or by adding workspace members directly. See Managing Your Organization.
Enforced capture and Required SSO are different settings. Capture
controls enrollment; Required SSO controls authentication for the linked
domain.
Link a Domain to SSO
Create or manage a configuration in SAML SSO Configurations on the same page. Under Domains (optional), choose a verified domain and set its sign-in policy. A domain already linked to another configuration is shown as in use; pending domains must be verified first. For the full setup and enforcement steps, see SAML SSO Setup.Troubleshooting
The DNS check fails
The DNS check fails
Check that the TXT record is published at the exact domain you entered and
that its value matches Krea’s token. Allow time for DNS propagation before
retrying. Keep unrelated TXT records, such as email authentication records,
in place.
I can't add or change domains
I can't add or change domains
Check your organization role and plan capabilities. If the page shows
Managed by Krea, contact support.
I see Workspace Domains as well as organization domains
I see Workspace Domains as well as organization domains
Workspace Domains lists older workspace-level domain settings. Use
organization domains for the organization setup described here. Contact Krea
if you need help consolidating an older configuration.
A verified domain did not enroll my teammates
A verified domain did not enroll my teammates
New organization domains default to capture Off. Choose Optional or
Enforced deliberately, then check workspace access separately.