For the complete documentation index, see llms.txt. This page is also available as Markdown.

How to Choose an Authorization Method

This document explains how to choose the correct sign-in, SSO, MFA, or API access method in DocStudio.

Use this page when you know who needs access to DocStudio, but you have not chosen the access method yet.

Before you start

Before you choose a method, define:

  1. Who needs access.

  2. Whether access is personal or company-managed.

  3. Whether the user signs in directly or through a third-party provider.

  4. Whether the company requires SSO.

  5. Whether MFA is needed.

  6. Whether access is needed for the interface or for API requests.

Then use the table below to choose the method and open the related instruction.

What users often confuse

  • Google sign-in is not the same as Google SSO setup.

  • Microsoft / Azure sign-in is not the same as Azure SSO setup.

  • MFA is not a primary sign-in method.

  • Application tokens are not used for interactive sign-in.

Choose the right method

User task
Use
Avoid
Go to

Sign in with a standard DocStudio account

Email and password

SSO or provider sign-in when the user does not use that setup

Sign in with Google

Google sign-in

password reset when the issue is with Google authorization

Sign in with Microsoft or Azure

Microsoft / Azure sign-in

Azure SSO setup when the user only needs the Microsoft sign-in button

Sign in with Apple ID

Apple sign-in

password reset when the issue is with Apple authorization

Sign in through a company identity provider

SSO

Google, Microsoft / Azure, or Apple sign-in when the company requires SSO

Configure company SSO with Azure

Azure SSO setup

Microsoft / Azure sign-in when the task is company SSO configuration

Configure company SSO with Google

Google SSO setup

Google sign-in when the task is company SSO configuration

Add extra verification during sign-in

MFA

MFA as the main sign-in method

Control password requirements

Password policy

manual password rules outside account settings

Authorize API requests

Application tokens

application tokens for regular user sign-in

Manage automated access

Integrations and API access

password sharing or manual sign-in for API flows

After you choose a method, use the scenarios below to confirm the correct flow.

Typical scenarios

Sign in a personal account

Goal: Access a personal DocStudio account without company-managed SSO.

Use:

  • email and password

  • Google sign-in

  • Microsoft / Azure sign-in

  • Apple sign-in

Do not use:

  • SSO when the user does not belong to a company SSO setup

  • application tokens for interface access

  • admin SSO setup instructions for a personal sign-in issue

Go to:

Sign in as a corporate user

Goal: Access a company workspace with the configured company method.

Use:

  • email and password, if the company allows it

  • Google sign-in, if the company uses it

  • Microsoft / Azure sign-in, if the company uses it

  • SSO, if the company requires it

Do not use:

  • personal account registration when the user must access company data

  • application tokens for interface access

  • password reset as the only fix when the company requires SSO

Go to:

Choose the correct invitation flow

Goal: Start the correct first login flow from an invitation.

Use:

  • the standard sign-in flow, if the invite is for regular account access

  • the company SSO flow, if the invite is tied to company SSO

  • the company-configured provider flow, if the company uses it

Do not use:

  • password reset before you confirm the expected access method

  • personal registration when the invite is for a company workspace

  • application tokens for first login

Go to:

Sign in with a third-party provider

Goal: Sign in through Google, Microsoft / Azure, or Apple.

Use:

  • Google sign-in

  • Microsoft / Azure sign-in

  • Apple sign-in

Do not use:

  • SSO setup instructions when the user only needs a provider button

  • password reset when the problem is with the provider flow

  • application tokens for user sign-in

Go to:

Sign in through SSO

Goal: Access DocStudio through company-managed authentication.

Use:

  • SSO on the sign-in page

  • the SSO invitation flow

  • the company identity provider flow

Do not use:

  • Google, Microsoft / Azure, or Apple sign-in when the company requires SSO

  • application tokens for interactive sign-in

  • personal account registration after an SSO invitation

Go to:

Configure Azure SSO for a company

Goal: Connect DocStudio to Azure-based company identity management.

Use:

  • Azure SSO SAML 2.0

  • Azure SSO OAuth 2.0

  • SSO provider configuration

Do not use:

  • Microsoft / Azure sign-in when the task is company SSO setup

  • personal user sign-in guidance for admin setup

  • application tokens for user authentication

Go to:

Configure Google SSO for a company

Goal: Connect DocStudio to Google-based company identity management.

Use:

  • Google SSO setup

  • SSO provider configuration

Do not use:

  • Google sign-in when the task is company SSO setup

  • email and password when company policy requires SSO

  • application tokens for user sign-in

Go to:

Require additional verification with MFA

Goal: Add an extra verification step to sign-in.

Use:

  • MFA

Do not use:

  • MFA as the main sign-in method

  • MFA instead of email and password, provider sign-in, or SSO

  • application tokens as a replacement for MFA

Go to:

Authorize API requests

Goal: Authorize API requests without sharing a user password.

Use:

  • application tokens

  • integrations and API access

Do not use:

  • application tokens for regular interface sign-in

  • user password sharing for integrations

  • SSO setup as a replacement for API authorization

Go to:

User sign-in methods

Email and password

Use email and password when a user signs in with standard DocStudio credentials.

When to use: Use this method when the user has a DocStudio account and wants to sign in directly.

Best for:

  • standard sign-in

  • users who do not use a provider sign-in method

  • users who do not need company SSO

Do not use this when:

  • the user signs in with Google, Microsoft / Azure, or Apple

  • the company requires SSO

  • the task is API access

Go to:

Google sign-in

Use Google sign-in when the user wants to access DocStudio through a Google account.

When to use: Use this method when the sign-in page shows the Google button and the user’s DocStudio access is connected to a Google account.

Best for:

  • users who use Google as their sign-in provider

  • users who do not want a separate DocStudio password

  • organizations that allow Google-based access

Do not use this when:

  • the company requires a separate SSO flow

  • the user needs Microsoft / Azure, Apple, or email and password

  • the task is API access

Go to:

Microsoft / Azure sign-in

Use Microsoft / Azure sign-in when the user wants to access DocStudio through a Microsoft or Azure account.

When to use: Use this method when the sign-in page shows the Microsoft button and the user’s DocStudio access is connected to a Microsoft or Azure account.

Best for:

  • users who use Microsoft accounts

  • users whose company allows Microsoft / Azure sign-in

  • users who do not want a separate DocStudio password

Do not use this when:

  • the company requires a separate SSO flow

  • the task is to configure Azure SSO

  • the task is API access

Go to:

Apple sign-in

Use Apple sign-in when the user wants to access DocStudio through Apple ID.

When to use: Use this method when the sign-in page shows the Apple button and the user’s DocStudio access is connected to Apple ID.

Best for:

  • users who use Apple ID as their sign-in provider

  • users who access the profile through Apple sign-in

Do not use this when:

  • the user must access DocStudio through company SSO

  • the user selected Hide My Email and DocStudio cannot complete the flow

  • the task is API access

Go to:

SSO

Use SSO when the company requires users to access DocStudio through a corporate identity provider.

When to use: Use this method when the user received an SSO invitation or the company requires SSO for access.

Best for:

  • corporate users

  • company-managed access

  • centralized authentication

  • admin-controlled security policies

Do not use this when:

  • the user only needs Google, Microsoft / Azure, or Apple sign-in

  • the user has only a personal account

  • the task is API access through application tokens

Go to:

Company SSO setup

Azure SSO setup

Use Azure SSO setup when a company needs to connect DocStudio to Azure-based identity management.

When to use: Use Azure SSO setup when an admin or technical team configures company-level SSO.

Best for:

  • companies that use Azure or Microsoft identity services

  • corporate users who must authenticate through company identity rules

  • centralized identity management

Do not use this when:

  • a user only needs Microsoft / Azure sign-in on the sign-in page

  • a personal user just needs to sign in

  • the task is API access

Go to:

Google SSO setup

Use Google SSO setup when a company needs to connect DocStudio to Google-based identity management.

When to use: Use Google SSO setup when an admin or technical team configures company-level SSO.

Best for:

  • companies that use Google Workspace or Google identity services

  • corporate users who must authenticate through company identity rules

  • centralized identity management

Do not use this when:

  • a user only needs Google sign-in on the sign-in page

  • a personal user just needs to sign in

  • the task is API access

Go to:

Security settings

MFA

Use MFA when sign-in requires an additional verification step.

When to use: Use MFA to add extra protection to sign-in.

Best for:

  • stronger account protection

  • corporate accounts with stricter security requirements

  • sign-in flows that need an extra check

Do not use this when:

  • you need to choose the main sign-in method

  • you need API access

  • you need to configure an SSO provider connection

Go to:

Password policy

Use password policy when a company needs to control password requirements.

When to use: Use password policy when security rules must define password complexity, expiration, or reuse behavior.

Best for:

  • corporate accounts

  • admin-managed security settings

  • organizations with stricter password requirements

Do not use this when:

  • the issue is SSO provider setup

  • the user signs in only through a provider-based flow

  • the task is API access

Go to:

API access

Application tokens

Use application tokens when API requests or third-party integrations need authorization.

When to use: Use application tokens for API access, not for regular user sign-in.

Best for:

  • developers

  • API requests

  • third-party integrations

  • automated processes

Do not use this when:

  • a user needs to sign in to the DocStudio interface

  • a company needs SSO setup

  • a user forgot their password

  • the user needs MFA for interactive sign-in

Go to:

Common mistakes

Avoid these mistakes when you choose an access method:

  • Using Google sign-in when the task is Google SSO setup.

  • Using Microsoft / Azure sign-in when the task is Azure SSO setup.

  • Using application tokens for regular user sign-in.

  • Using MFA as the main sign-in method.

  • Using email and password when the company requires SSO.

  • Using SSO setup instructions when the user only needs to click Google, Microsoft / Azure, or Apple on the sign-in page.

  • Using a personal access flow for a corporate user who received an SSO invitation.

  • Resetting the password when the real issue is company SSO configuration.

  • Configuring SSO when the task only needs API access through an application token.

  • Using user passwords in integrations instead of application tokens.

Quick decision guide

Use these rules to choose faster:

  • If the user has a standard DocStudio account, use email and password.

  • If the user signs in through Google, use Google sign-in.

  • If the user signs in through Microsoft or Azure, use Microsoft / Azure sign-in.

  • If the user signs in through Apple ID, use Apple sign-in.

  • If the company manages access through a corporate identity provider, use SSO.

  • If the company uses Azure for identity management, configure Azure SSO setup.

  • If the company uses Google for identity management, configure Google SSO setup.

  • If sign-in needs an extra verification step, use MFA.

  • If the task is API access, use application tokens.

  • If password rules must be stricter, configure password policy.

User sign-in

Company SSO setup

Security settings

API access

Last updated