Platform SSO, brokered

Native Mac sign-in
for any identity provider.

psso.app brokers Apple's Platform SSO to Google Workspace and any OIDC provider. Your team signs in to their Mac with the identity they already use — delivered through your MDM, with zero per-tenant infrastructure.

Secure Enclave–backed keys · Apple's JOSE protocol end-to-end
psso.app
Signed in with Google Workspace
🔒 Registered on this Mac
The gap Apple left open

Apple built loginwindow SSO. We made it work with your IdP.

Platform SSO lets the macOS loginwindow authenticate against a cloud identity provider — but only a handful of IdPs are natively supported. psso.app is the broker that speaks Apple's protocol on one side and standard OIDC on the other, so any provider fits.

How it works

Three steps. Zero servers per tenant.

Everything ships through the fleet management you already run. A tenant is configuration — not infrastructure.

01 — DEPLOY

Ship it through MDM

Push the psso.app configuration and app to your Macs. It installs during Setup Assistant, so SSO is ready before the first login.

02 — REGISTER

Bind the device

The Mac registers with the broker using a hardware-bound Secure Enclave key. Per-device tokens, no shared secrets.

03 — SIGN IN

Authenticate at the loginwindow

Your team signs in against your IdP. The broker exchanges Apple's login request for standard OIDC — and keeps the session alive.

💻
Managed MacPlatform SSO extension
🔐
psso.app brokerApple JOSE ⇄ OIDC
🪪
Your identity providerGoogle Workspace, OIDC
What you get

Built for the way Apple fleets actually work.

🖥️

Native loginwindow SSO

Not a menu-bar agent or a browser tab — the real macOS sign-in screen, authenticating against your directory.

🔗

Any identity provider

Google Workspace today; Okta, Microsoft Entra, Ping, and any OIDC provider next. One broker, every IdP.

☁️

Zero per-tenant infrastructure

Tenants are config, not servers. Nothing to stand up, patch, or scale for each customer.

🎨

Your brand, in Apple's dialogs

Your name and identity render inside macOS's own registration and sign-in screens — no re-signing per tenant.

📦

Delivered through MDM

Ships with your device management and works from the very first login, held in place during Setup Assistant.

🛡️

Hardware-bound security

Secure Enclave–backed device keys, per-device refresh tokens, and Apple's JOSE protocol end to end.

Security by design

Keys in the Secure Enclave.
Tokens per device.

The broker holds a customer's IdP connection, never a user's password. Device identity is bound to Apple silicon and can be revoked the moment a Mac leaves the fleet.

Secure Enclave keys Per-device refresh tokens Apple JOSE / JWE MDM-managed associated domains Revoke on unenroll Isolated, per-tenant config
Works with

Bring the identity you already run.

Google Workspace Okta Microsoft Entra Ping OneLogin Auth0 Any OIDC provider

Google Workspace available first · additional providers on the roadmap

Bring single sign-on to the loginwindow.

psso.app is in active development. Request early access and we'll get your fleet set up with brokered Platform SSO.