For Members
Before you start, you need:- The latest version of Reagent (0.15.1 or later). Download Reagent.
- Your work email address, on your company’s email domain.
- Your organization’s endpoint details from your IT team: the Endpoint URL, API key and Model ID. Reagent asks for them after you sign in.
Sign In With SSO
Always start sign-in from the Reagent app. SSO doesn’t work on the reaperagent.com website.Start sign-in in the app
Enter your work email
Sign in with your company account
Return to Reagent
Finish setup
- New to Reagent? Answer a few welcome questions.
- Enter your endpoint details in the Custom Endpoint window. You can’t use Reagent until an endpoint works. You enter them once on each computer, and again after you log out. See Custom Endpoint.
- Connect Reagent to REAPER, as on any plan. See Quick Start.
Your First SSO Sign-In
Your first SSO sign-in creates your Reagent account. If you already have an account with a password, it converts that account to SSO instead:- Your password stops working. From now on, you sign in with SSO.
- Reagent signs you out on your other computers and removes your endpoint details there, so you enter them again when you next sign in there.
- Your profile stays the same. Your chats stay too, because they’re stored on your computer.
Sign In With a Password
The sign-in page asks for your password instead of offering SSO when:- You’re exempt. At your organization’s request, Reagent’s team can exempt people such as contractors, or shared and test accounts. SSO isn’t available to you. No password yet? Click Forgot password? on the sign-in page to set one.
- SSO isn’t switched on for your domain yet, or it’s been switched off. With no account yet, the page says “No account found for this email.” and you can click Sign up.
Log Out
Click your name at the bottom of Reagent’s sidebar, then click Log out. The Sign out button in the Custom Endpoint window does the same. Logging out:- Signs you out of Reagent on all your computers, not only this one.
- Removes your organization’s endpoint settings, including the API key, from each computer as it’s signed out. You enter them again the next time you sign in there.
Troubleshooting Sign-In
To restart sign-in, go back to Reagent, click Cancel if it’s still waiting, and click Sign in to Reagent again.“Open the Reagent app to sign in with single sign-on”
“Open the Reagent app to sign in with single sign-on”
The website's sign-up page sends you to sign in
The website's sign-up page sends you to sign in
“Could not start SSO sign-in. Please try again.”
“Could not start SSO sign-in. Please try again.”
The page asks for a password instead of showing Continue with
The page asks for a password instead of showing Continue with
“This account signs in with email and password instead of single sign-on”
“This account signs in with email and password instead of single sign-on”
“This account uses single sign-on. Please continue with SSO instead.”
“This account uses single sign-on. Please continue with SSO instead.”
“This account signs in with single sign-on. Open the Reagent app to sign in.”
“This account signs in with single sign-on. Open the Reagent app to sign in.”
Forgot password says the account has no password to reset
Forgot password says the account has no password to reset
The browser doesn't return to Reagent
The browser doesn't return to Reagent
Sign-in took longer than 10 minutes
Sign-in took longer than 10 minutes
“Your sign-in session expired before it could complete”
“Your sign-in session expired before it could complete”
“This account isn't set up for single sign-on with your organization”
“This account isn't set up for single sign-on with your organization”
“Your organization has reached its Reagent seat limit”
“Your organization has reached its Reagent seat limit”
“Your single sign-on attempt could not be completed”
“Your single sign-on attempt could not be completed”
Your first SSO sign-in created a new account
Your first SSO sign-in created a new account
“Your organization's Reagent license has ended”
“Your organization's Reagent license has ended”
“Your session ended. Sign in again.”
“Your session ended. Sign in again.”
For IT Admins
Before you set up SSO, know how it works with Reagent:- WorkOS. Reagent uses WorkOS for SSO. You connect your identity provider through a WorkOS Admin Portal link from Reagent’s team. WorkOS is on Reagent’s subprocessors page.
- One email domain per organization, such as
studio.com. Once SSO is switched on (enforced), anyone who types an email at that domain on the sign-in page goes to your identity provider, unless they’re exempt. - SSO is the way in. Once SSO is switched on, Reagent’s sign-in page offers people at your domain who aren’t exempt no password sign-in and no password reset, so they sign in through your identity provider.
- Email addresses must be at your domain exactly. Reagent reads each person’s email address from your identity provider and refuses other domains, including subdomains, with “This account isn’t set up for single sign-on with your organization.” It matches existing accounts by email address (capitalization doesn’t matter), so a different address, such as an alias, creates a second account instead of converting the existing one, and uses a second seat.
- Sign-in starts in the Reagent app. IdP-initiated sign-in (from your identity provider’s app dashboard) doesn’t work, and there’s no SSO sign-in to the reaperagent.com website.
- Reagent’s team manages your organization: the seat limit, exemptions and account removal. People can’t delete their own Enterprise account. There’s no self-serve admin console and no SCIM or directory sync.
- Access ends with your license, at the exact moment your contract ends. See When Your License Ends.
Set Up SSO
Before you start, have your organization’s AI endpoint ready and tested. When Reagent’s team creates your organization, every existing Reagent account with an email at your domain becomes an Enterprise account, even before SSO is switched on. Those people then need your organization’s endpoint details to keep chatting in Reagent.Contact Reagent's team
- your company email domain
- the organization name people should see on the sign-in page
- anyone who should keep signing in with a password (see Exemptions)
- a seat limit, if you want one
Connect your identity provider
Tell Reagent's team you're done
Tell your team
Change your SSO connection later
Change your SSO connection later
Seats
Your organization has no seat limit unless Reagent’s team sets one. To change it, contact Reagent’s team.- A person’s first SSO sign-in uses a seat, whether it creates a new account or converts an existing one. Signing in again never uses another.
- People who sign in with a password and have never signed in with SSO don’t use a seat.
- When Reagent’s team removes someone’s account, its seat becomes free again.
- At the limit, new people see the seat-limit message. People who already have an SSO account keep signing in as normal.
Exemptions
Reagent’s team can exempt people who can’t use your identity provider, such as contractors, or shared and test accounts. Send the list before SSO is switched on, so they can keep signing in from the first day.- An exempt person signs in with email and password, and SSO is refused for them. They still have an Enterprise account.
- If an exempt person has no Reagent account yet, Reagent’s team can create one.
- Accounts that Reagent’s team creates, and accounts exempted after they switched to SSO, have no password yet. The person clicks Forgot password? on the sign-in page to set one.
Removing Someone’s Access
Reagent has no directory sync, so changes in your identity provider don’t change Reagent accounts. Removing someone in your identity provider also doesn’t sign them out of Reagent on a computer where they’re already signed in. To remove someone’s access, do these in order:- Remove them from Reagent in your identity provider (unassign them from the Reagent app), so they can’t sign in through it again. If you skip this and only ask for the account to be removed, their next SSO sign-in creates a new one and uses a seat.
- Revoke their API key. If they have their own API key for your organization’s endpoint, revoke it in your AI gateway. This stops their use of your model right away: until Reagent signs them out, it keeps using the key saved on their computer.
- Ask Reagent’s team to remove their Reagent account. Reagent’s team deletes the account permanently, which frees its seat. Any computer where the person is still signed in is signed out within an hour, and Reagent removes your endpoint details from it.