Run your headshot rollout through your identity provider

SAML 2.0 single sign-on, domain enforcement, JIT provisioning, and MFA for admins, all included with Teams. Everyone signs in through the identity provider you already manage.

Create your team
Security Admin · Settings
All systems enforced
Single Sign-On (SSO) Enabled
Ok
Okta
SAML 2.0
Connected
acme.com Verified
Require SSO login
Auto-join (JIT Provisioning)
MFA for team admins
Admins verify with a 6-digit email code.
Recent auth events
sso.login.succeeded j.alvarez@acme.com 2 min ago
sso.login.succeeded p.osei@acme.com 14 min ago
sso.login.succeeded m.chen@acme.com 31 min ago

The identity controls your IT team expects

No passwords, by default

Every invite is a magic link sent to the member's work email. Members never create a password, so there's no credential to leak, reset, or store, and if the inbox already sits behind your SSO or MFA, their HeadshotPro access gets the same protection.

Inbox
H
HeadshotPro
to m.chen@acme.com
You're invited to Acme Inc.'s team headshots
Accept your invite
This link expires in 2 hours.

Or put the whole org behind your SSO

HeadshotPro's single sign-on is backed by WorkOS and supports SAML 2.0 and OAuth, so if your identity provider speaks SAML, it connects. Setup, domain verification, and certificate rotations all run through a hosted configuration portal, no support ticket needed.

Connect your identity provider
En Microsoft Entra ID
Ok Okta
Go Google Workspace
+ Other SAML 2.0 provider
ACS URL
https://auth.headshotpro.com/sso/acs Copy
Entity ID
urn:headshotpro:sp:acme Copy

Make your identity provider the only way in

Verify your domain and switch on Require SSO, and anyone with a company email can no longer sign in with a password or a Google or LinkedIn account. The change applies immediately to new sign-ins, and you can relax it temporarily during a migration window or for service accounts.

Require SSO: ON
Sign in to HeadshotPro
m.chen@acme.com
••••••••
acme.com requires single sign-on
Continue with Okta
Google
LinkedIn

New hires provision themselves on first sign-in

With JIT provisioning on, the first successful SSO authentication creates the HeadshotPro account and adds the person to your organization, without an invite or an admin stepping in. Leave it off and membership stays invite-only. SCIM provisioning is available on request.

Auto-join (JIT Provisioning) On
Step 1
Ok Okta sign-in
d.okafor@acme.com
Step 2
Account created. Added to Acme Inc.
Step 3
DO
D. Okafor
Joined just now
Joined

A second factor for the accounts that can delete data

Admin accounts can remove members, transfer ownership, and wipe photo data, so they get extra protection. Enforce MFA and every org admin verifies with a 6-digit email code on their first sign-in after a 24-hour gap. Members aren't affected, since their security comes from your IdP.

Verify it's you
We sent a code to a•••@acme.com
3921
Verify
Code expires in 10 minutes

Answers ready for the security questionnaire

Every SSO authentication event lands in a filterable audit log. Behind it are the details procurement asks about: SOC 2 Type II, GDPR compliance, and a DPA available on request. The full picture is on the security page.

SOC 2 Type II GDPR DPA on request
Event type: All Last 30 days
sso.login.succeeded j.alvarez@acme.com
sso.login.succeeded p.osei@acme.com
sso.login.failed r.kapoor@acme.com
sso.login.succeeded m.chen@acme.com

8,000+ employees across 135+ countries

The headshots are excellent, the process couldn't be easier, and the customized support from Danny and his team has been outstanding. It's a product that keeps getting better and one I'm thrilled to recommend!
HubSpot logo
Brenda Fridman
Sales Director, HubSpot
Read the HubSpot story

Questions IT teams ask

  • What does Advanced Identity cost?

    It's included with Teams credits, with no separate platform fee or subscription. Contact sales to have SSO activated for your organization. Volume discounts run from 20% at 6 credits up to 60% at 200+; see pricing for the full table.

  • Which identity providers does the SSO support?

    Microsoft Entra ID, Okta, Google Workspace, and any SAML 2.0-compatible provider. The connection is backed by WorkOS, and configuration runs through a hosted portal where you also verify domains and rotate certificates.

  • Do you support SCIM provisioning?

    Out of the box, provisioning is just-in-time: an account is created on first SSO authentication. SCIM can be implemented on request for organizations that need directory-driven provisioning and deprovisioning. Raise it with sales.

  • What happens to people who are already signed in when I enforce SSO?

    Require SSO applies immediately to new sign-ins. Anyone already logged in keeps their session until it expires, then authenticates through your IdP. You can switch enforcement off temporarily during a migration or for service accounts.

  • What does the audit log cover?

    SSO authentication events: event type, user email, timestamp, and metadata, filterable by event type and date range. It's not a general admin-action log. For rollout reporting, use the CSV export from the team dashboard.

  • How does MFA for admins work?

    Email-based: a 6-digit code on the first sign-in after a 24-hour gap. Codes expire after 10 minutes and allow 5 attempts. It applies to admin accounts only, so members aren't prompted, and there's no SMS or authenticator-app option.

  • Do team members get a password?

    No. Members join through a magic link sent to their work email that expires after two hours, and they re-enter the same way. There's no member password to manage or breach. If their email sits behind your SSO or MFA, that protection extends to their HeadshotPro access automatically.

  • What happens to my team's photos?

    Your photos are never used to train AI models. Input photos auto-delete 30 days after generation, and you can enable 30-day auto-deletion of all member shoot data for the whole organization. HeadshotPro operates as data processor under GDPR, with your organization as controller. A DPA is available on request.

Set up your team behind your IdP

Create the organization, connect your identity provider in the configuration portal, and every sign-in after that runs through the system you already audit.

Create your team
See pricing Read the docs