How do I sign in with SSO for the first time?

How do I sign in with SSO for the first time?


The screenshots in this article show the German interface. The English label is given first, with the German label in square brackets.


Your organisation has set up single sign-on (SSO) — from now on you sign in to ContractHero with your company account (for example Microsoft Entra) instead of with a separate password. This article shows what you have to do on your first SSO login so that your existing ContractHero account is linked correctly to your company account.


Your benefit


No second password to remember, no separate logout/login loops — you sign in to your company account once a day and use ContractHero straight away. At the same time, your organisation benefits from centrally managed MFA and clean offboarding (anyone who leaves the company automatically loses access to ContractHero).


Requirements


  • You already have an existing ContractHero account (invitation received, password set, signed in at least once).
  • The owner of your organisation has set up custom SSO and you have been informed that password login is being switched off (or already has been).
  • You know your organisation-specific ContractHero URL (for example <prefix>.app.contracthero.com).


How it works


1. Open your organisation-specific URL


Go to your custom URL (you will receive the exact address from your owner). The sign-in page now shows "Login via OpenID Connect" as the only option — the standard password field is hidden.






2. Select "Login via OpenID Connect"


Click the button and sign in with your company account (for example Microsoft Entra / Microsoft 365). If you are already signed in in your browser, this works without entering a password again.


3. Confirm the account link (first login only!)


On your first SSO login, ContractHero asks you for your ContractHero email address and your ContractHero password — this is what links your existing account to your company account. Enter those details.


Why the additional confirmation? Without this one-off confirmation, ContractHero would create a second account with the same email address — which is not possible for data-protection and uniqueness reasons. The link is made only once; after that, the SSO login is all you need.


4. Done — SSO only from now on


Your ContractHero account is now linked to your company account. For every subsequent login you simply click "Login via OpenID Connect" and you are in ContractHero within seconds — with no password to enter.


Frequently asked questions


Why can I no longer see a password field?
Your organisation has deactivated the classic password login because SSO is live. This is intended and a security improvement.


What if I have forgotten my ContractHero password when linking the accounts?
Click Forgot password [Passwort vergessen] and quickly set a new one — then repeat the linking step. You will not need the new password afterwards, because future logins run via SSO.


What if I have never had a ContractHero account?
Ask your owner to invite you officially — only with an invitation can you register and then complete the SSO link. Signing in via SSO alone, without a prior invitation, does not create an account automatically.


What if the email address in my company account is different from the one in ContractHero?
The accounts are linked by email address. If the addresses do not match, ask your owner whether the address in ContractHero can be updated to your current company address — the link will then go through cleanly.


What if the standard URL (app.contracthero.com) still works?
For owners, a password login via the standard URL is often kept active as a fallback. End users are directed to the organisation-specific URL — always use that one.


What happens if our SSO goes down?
If the identity provider (for example Microsoft Entra) is temporarily unreachable, the login fails. Owners may be able to sign in via the password login on the standard URL; regular members have to wait until the IdP is available again.


Good to know


  • Bookmark the organisation-specific URL. Save the custom URL as a browser bookmark — that stops you from accidentally starting at the standard URL and wondering where the password field has gone.
  • MFA happens at the company login, not in ContractHero. If your IT team enforces MFA in Microsoft Entra, the two-factor check is triggered once per session during the SSO login — there is no longer a separate MFA prompt in ContractHero itself.
  • Changing your password regularly is still worthwhile. Even though you no longer need the ContractHero password after linking, it should not be too old, as a fallback (for example if SSO goes down). The forgot-password function remains available.
  • When in doubt, talk to your owner. If the first SSO login does not work, or you are not sure whether the link went through cleanly, contact the owner of your organisation — the problem can often be solved in two minutes.



  • How do I set up SSO? (Microsoft Entra / Azure AD)
  • Microsoft Entra: renewing the client secret for ContractHero SSO
  • How can roles and permissions be managed for additional users?

Updated on: 08/26/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!