Native Mac sign-in
for any identity provider.
psso.app brokers Apple's Platform SSO to Google Workspace and any OIDC provider. Your team signs in to their Mac with the identity they already use — delivered through your MDM, with zero per-tenant infrastructure.
Apple built loginwindow SSO. We made it work with your IdP.
Platform SSO lets the macOS loginwindow authenticate against a cloud identity provider — but only a handful of IdPs are natively supported. psso.app is the broker that speaks Apple's protocol on one side and standard OIDC on the other, so any provider fits.
Three steps. Zero servers per tenant.
Everything ships through the fleet management you already run. A tenant is configuration — not infrastructure.
Ship it through MDM
Push the psso.app configuration and app to your Macs. It installs during Setup Assistant, so SSO is ready before the first login.
Bind the device
The Mac registers with the broker using a hardware-bound Secure Enclave key. Per-device tokens, no shared secrets.
Authenticate at the loginwindow
Your team signs in against your IdP. The broker exchanges Apple's login request for standard OIDC — and keeps the session alive.
Built for the way Apple fleets actually work.
Native loginwindow SSO
Not a menu-bar agent or a browser tab — the real macOS sign-in screen, authenticating against your directory.
Any identity provider
Google Workspace today; Okta, Microsoft Entra, Ping, and any OIDC provider next. One broker, every IdP.
Zero per-tenant infrastructure
Tenants are config, not servers. Nothing to stand up, patch, or scale for each customer.
Your brand, in Apple's dialogs
Your name and identity render inside macOS's own registration and sign-in screens — no re-signing per tenant.
Delivered through MDM
Ships with your device management and works from the very first login, held in place during Setup Assistant.
Hardware-bound security
Secure Enclave–backed device keys, per-device refresh tokens, and Apple's JOSE protocol end to end.
Keys in the Secure Enclave.
Tokens per device.
The broker holds a customer's IdP connection, never a user's password. Device identity is bound to Apple silicon and can be revoked the moment a Mac leaves the fleet.
Bring the identity you already run.
Google Workspace available first · additional providers on the roadmap
Bring single sign-on to the loginwindow.
psso.app is in active development. Request early access and we'll get your fleet set up with brokered Platform SSO.