> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.contracthero.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How do I sign in with SSO for the first time?

# How do I sign in with SSO for the first time?

*The screenshots in this article show the German interface. The English label is given first, with the German label in square brackets.*

Your organisation has set up single sign-on (SSO) — from now on you sign in to ContractHero with your company account (for example Microsoft Entra) instead of with a separate password. This article shows what you have to do on your first SSO login so that your existing ContractHero account is linked correctly to your company account.

## Your benefit

No second password to remember, no separate logout/login loops — you sign in to your company account once a day and use ContractHero straight away. At the same time, your organisation benefits from centrally managed MFA and clean offboarding (anyone who leaves the company automatically loses access to ContractHero).

## Requirements

* You already have an **existing ContractHero account** (invitation received, password set, signed in at least once).
* The owner of your organisation has **set up custom SSO** and you have been informed that password login is being switched off (or already has been).
* You know your **organisation-specific ContractHero URL** (for example `<prefix>.app.contracthero.com`).

## How it works

**1. Open your organisation-specific URL**

Go to your custom URL (you will receive the exact address from your owner). The sign-in page now shows **"Login via OpenID Connect"** as the only option — the standard password field is hidden.


![](https://storage.crisp.chat/users/helpdesk/website/-/1/2/5/2/12522a019f980500/screenshot-2026-07-03-at-15472_1ol53l8.png)



**2. Select "Login via OpenID Connect"**

Click the button and sign in with your **company account** (for example Microsoft Entra / Microsoft 365). If you are already signed in in your browser, this works without entering a password again.

**3. Confirm the account link (first login only!)**

On your **first** SSO login, ContractHero asks you for your **ContractHero email address and your ContractHero password** — this is what links your existing account to your company account. Enter those details.

> **Why the additional confirmation?** Without this one-off confirmation, ContractHero would create a **second account** with the same email address — which is not possible for data-protection and uniqueness reasons. The link is made only once; after that, the SSO login is all you need.

**4. Done — SSO only from now on**

Your ContractHero account is now linked to your company account. For every subsequent login you simply click **"Login via OpenID Connect"** and you are in ContractHero within seconds — with no password to enter.

## Frequently asked questions

**Why can I no longer see a password field?**
Your organisation has deactivated the classic password login because SSO is live. This is intended and a security improvement.

**What if I have forgotten my ContractHero password when linking the accounts?**
Click **Forgot password [Passwort vergessen]** and quickly set a new one — then repeat the linking step. You will not need the new password afterwards, because future logins run via SSO.

**What if I have never had a ContractHero account?**
Ask your owner to invite you officially — only with an invitation can you register and then complete the SSO link. Signing in via SSO alone, without a prior invitation, does not create an account automatically.

**What if the email address in my company account is different from the one in ContractHero?**
The accounts are linked by email address. If the addresses do not match, ask your owner whether the address in ContractHero can be updated to your current company address — the link will then go through cleanly.

**What if the standard URL (`app.contracthero.com`) still works?**
For owners, a password login via the standard URL is often kept active as a fallback. End users are directed to the organisation-specific URL — always use that one.

**What happens if our SSO goes down?**
If the identity provider (for example Microsoft Entra) is temporarily unreachable, the login fails. Owners may be able to sign in via the password login on the standard URL; regular members have to wait until the IdP is available again.

## Good to know

* **Bookmark the organisation-specific URL.** Save the custom URL as a browser bookmark — that stops you from accidentally starting at the standard URL and wondering where the password field has gone.
* **MFA happens at the company login, not in ContractHero.** If your IT team enforces MFA in Microsoft Entra, the two-factor check is triggered once per session during the SSO login — there is no longer a separate MFA prompt in ContractHero itself.
* **Changing your password regularly is still worthwhile.** Even though you no longer need the ContractHero password after linking, it should not be too old, as a fallback (for example if SSO goes down). The forgot-password function remains available.
* **When in doubt, talk to your owner.** If the first SSO login does not work, or you are not sure whether the link went through cleanly, contact the owner of your organisation — the problem can often be solved in two minutes.

## Related articles

* How do I set up SSO? (Microsoft Entra / Azure AD)
* Microsoft Entra: renewing the client secret for ContractHero SSO
* How can roles and permissions be managed for additional users?
