Private workspaces & SSO
Make your content private by enabling SSO authentication on a workspace. Only verified users from allowed email domains can access Hubs, Bites, and Pulse feeds.
What is a private workspace?
By default, published content in a workspace is publicly accessible — anyone with the link can view it. A private workspace adds an authentication layer: visitors must sign in with an approved email domain before they can see any content.
Public workspace
Anyone with the link can view content. Best for marketing, help centers, and public documentation.
Private workspace
Only authenticated users from allowed domains can access content. Best for customer training, internal knowledge, and premium content.
How SSO works
When SSO is enabled on a workspace:
- 1A visitor opens a Hub, Bite, or Pulse link.
- 2The system checks for a valid authentication token.
- 3If not authenticated, the visitor is redirected to a sign-in page.
- 4The visitor signs in with their email — only allowed domains are accepted.
- 5After authentication, the visitor is redirected back to the original content.
- 6The authentication token is stored as a cookie for seamless future visits.
Important:SSO protects all content in the workspace — Hubs, Bite player pages, embeds, and Pulse feeds. It’s not possible to make some content public and some private within the same workspace. Use separate workspaces if you need both.
Setting up SSO
SSO setup is handled by the DemoBites team. Contact us to enable SSO on your workspace:
Email domain allowlist
Specify which email domains are allowed to authenticate (e.g., @acme.com, @partner.com).
Seat limit
Set the maximum number of authenticated users for your workspace.
Custom domain
Optionally serve content from your own domain for a fully white-labeled experience.
User experience
The sign-in process is designed to be frictionless:
- No passwords — email-based verification keeps things simple.
- Session cookies persist across visits, so returning users go straight to content.
- The sign-in page is branded with your workspace identity (logo, colors).
- Failed sign-in attempts with non-allowed domains show a clear error message.
Domain allowlisting
You control exactly which email domains can access your private workspace. Add your company domain, client domains, or partner domains:
# Allowed domains
acme.com
partner-agency.com
consulting-firm.ioAnyone with an email address at these domains can sign in. Users with emails from other domains are denied access.
Pricing
Private workspaces with SSO are available as an add-on at $25/month per workspace. This includes the full SSO authentication flow, domain allowlisting, custom-branded sign-in page, and session management.