SAML 2.0 single sign-on, domain enforcement, JIT provisioning, and MFA for admins, all included with Teams. Everyone signs in through the identity provider you already manage.
Every invite is a magic link sent to the member's work email. Members never create a password, so there's no credential to leak, reset, or store, and if the inbox already sits behind your SSO or MFA, their HeadshotPro access gets the same protection.
HeadshotPro's single sign-on is backed by WorkOS and supports SAML 2.0 and OAuth, so if your identity provider speaks SAML, it connects. Setup, domain verification, and certificate rotations all run through a hosted configuration portal, no support ticket needed.
Verify your domain and switch on Require SSO, and anyone with a company email can no longer sign in with a password or a Google or LinkedIn account. The change applies immediately to new sign-ins, and you can relax it temporarily during a migration window or for service accounts.
With JIT provisioning on, the first successful SSO authentication creates the HeadshotPro account and adds the person to your organization, without an invite or an admin stepping in. Leave it off and membership stays invite-only. SCIM provisioning is available on request.
Admin accounts can remove members, transfer ownership, and wipe photo data, so they get extra protection. Enforce MFA and every org admin verifies with a 6-digit email code on their first sign-in after a 24-hour gap. Members aren't affected, since their security comes from your IdP.
Every SSO authentication event lands in a filterable audit log. Behind it are the details procurement asks about: SOC 2 Type II, GDPR compliance, and a DPA available on request. The full picture is on the security page.
8,000+ employees across 135+ countries
The headshots are excellent, the process couldn't be easier, and the customized support from Danny and his team has been outstanding. It's a product that keeps getting better and one I'm thrilled to recommend!
It's included with Teams credits, with no separate platform fee or subscription. Contact sales to have SSO activated for your organization. Volume discounts run from 20% at 6 credits up to 60% at 200+; see pricing for the full table.
Microsoft Entra ID, Okta, Google Workspace, and any SAML 2.0-compatible provider. The connection is backed by WorkOS, and configuration runs through a hosted portal where you also verify domains and rotate certificates.
Out of the box, provisioning is just-in-time: an account is created on first SSO authentication. SCIM can be implemented on request for organizations that need directory-driven provisioning and deprovisioning. Raise it with sales.
Require SSO applies immediately to new sign-ins. Anyone already logged in keeps their session until it expires, then authenticates through your IdP. You can switch enforcement off temporarily during a migration or for service accounts.
SSO authentication events: event type, user email, timestamp, and metadata, filterable by event type and date range. It's not a general admin-action log. For rollout reporting, use the CSV export from the team dashboard.
Email-based: a 6-digit code on the first sign-in after a 24-hour gap. Codes expire after 10 minutes and allow 5 attempts. It applies to admin accounts only, so members aren't prompted, and there's no SMS or authenticator-app option.
No. Members join through a magic link sent to their work email that expires after two hours, and they re-enter the same way. There's no member password to manage or breach. If their email sits behind your SSO or MFA, that protection extends to their HeadshotPro access automatically.
Your photos are never used to train AI models. Input photos auto-delete 30 days after generation, and you can enable 30-day auto-deletion of all member shoot data for the whole organization. HeadshotPro operates as data processor under GDPR, with your organization as controller. A DPA is available on request.
























































































































Create the organization, connect your identity provider in the configuration portal, and every sign-in after that runs through the system you already audit.
See pricing Read the docs