Signing in with single sign-on
If your organisation has turned on single sign-on (SSO), you sign in to GarageHQ through your company's identity provider, the same Microsoft, Google, Okta, or Auth0 account you already use for everything else at work. There's no separate GarageHQ password to remember.
This article is for members, the people who use GarageHQ day to day. If you're the organisation owner setting SSO up for the first time, see Configuring single sign-on instead.
How sign-in changes
Before SSO is enforced, the GarageHQ sign-in page shows a list of options: Microsoft, Google, sign in with a link sent to your email, and so on. You pick one and continue.
Once your organisation enforces SSO, that picker is skipped for anyone with a work email on a verified domain. You're redirected straight to your identity provider's familiar login screen, you sign in there, and you land back at GarageHQ already authenticated.
You may not see any extra steps if you're already signed in to your identity provider in this browser. The whole flow takes a fraction of a second.
What if I'm already signed in?
If you were already signed in to GarageHQ when your owner enforced SSO, your existing session continues to work until it expires (typically a few hours). The next time you need to sign in again, you'll be routed through your identity provider.
You don't need to sign out and back in to "switch over". The flip is automatic on your next sign-in.
What you might need to do once
The first time you sign in through SSO, your identity provider may ask you to:
- Approve the GarageHQ app, a one-off consent screen that lists which fields GarageHQ reads (your name, email, and profile). Click Accept or Allow.
- Complete multi-factor authentication, if your IdP requires MFA for new sign-ins. Your usual second factor, an authenticator code, a hardware key, or a phone prompt.
After that, sign-ins are usually one click.
I'm on a personal device
SSO works the same way on personal devices as on company laptops. You'll be redirected to your IdP, you'll sign in there with your work credentials (and any MFA your organisation requires), and you'll be sent back to GarageHQ.
If your identity provider blocks sign-ins from personal devices (some organisations do this with conditional access policies in Microsoft Entra ID, for example), you won't be able to sign in to GarageHQ from that device either. Speak to your IT team if you need access from a personal device but the IdP is blocking it.
What to expect if something goes wrong
If your identity provider rejects you, returns an error, or your account doesn't exist there, GarageHQ shows the error you saw at the IdP. You won't be able to "fall back" to the regular sign-in options on the picker page, that's the point of enforcement.
Common things you can fix yourself:
- You're using the wrong account at your IdP. Some browsers remember multiple accounts. Make sure the one selected matches your GarageHQ-registered email.
- You're using an email alias. If your work IdP signs you in as
you@brand.combut your real account is onyou@tenant.onmicrosoft.com, GarageHQ will see the second one, not the alias. Sign in with the canonical address. - Your account has been deactivated at the IdP. Same as everything else at work, when IT disables your account, you lose access here too. Speak to your IT team.
For everything else, contact the GarageHQ owner at your organisation. They have visibility of the Recent sign-in events log on the Settings → Single sign-on page and can usually see exactly why your sign-in failed.
Break-glass accounts
The organisation owner can nominate "break-glass" accounts, specific email addresses that always retain access to the regular sign-in picker, even when SSO is enforced. This exists so that someone can still get into GarageHQ when the identity provider has an outage.
If you've been told you're a break-glass account, you can sign in via app.garagehq.uk/login with whatever method was originally on your account (passwordless email, Microsoft, Google). You'll see the regular picker rather than being routed to the IdP.
I've left my organisation, what now?
When you leave an organisation, your IT team typically deactivates your IdP account. That immediately stops you signing in to GarageHQ through SSO.
If you still need access to GarageHQ as an individual, for example, to keep your personal vehicle records, ask the GarageHQ owner to remove you from the org rather than just deactivate you at the IdP. Once you're no longer a member of the SSO-enforced org, you can sign back in via the regular picker and keep your personal account.
If you were already removed from the org and you've lost access, contact hello@garagehq.uk, we can help recover the account.