How to Choose an Authorization Method
This document explains how to choose the correct sign-in, SSO, MFA, or API access method in DocStudio.
Use this page when you know who needs access to DocStudio, but you have not chosen the access method yet.
Before you start
Before you choose a method, define:
Who needs access.
Whether access is personal or company-managed.
Whether the user signs in directly or through a third-party provider.
Whether the company requires SSO.
Whether MFA is needed.
Whether access is needed for the interface or for API requests.
Then use the table below to choose the method and open the related instruction.
What users often confuse
Google sign-in is not the same as Google SSO setup.
Microsoft / Azure sign-in is not the same as Azure SSO setup.
MFA is not a primary sign-in method.
Application tokens are not used for interactive sign-in.
Choose the right method
Sign in with a standard DocStudio account
Email and password
SSO or provider sign-in when the user does not use that setup
Sign in with Google
Google sign-in
password reset when the issue is with Google authorization
Sign in with Microsoft or Azure
Microsoft / Azure sign-in
Azure SSO setup when the user only needs the Microsoft sign-in button
Sign in with Apple ID
Apple sign-in
password reset when the issue is with Apple authorization
Sign in through a company identity provider
SSO
Google, Microsoft / Azure, or Apple sign-in when the company requires SSO
Configure company SSO with Azure
Azure SSO setup
Microsoft / Azure sign-in when the task is company SSO configuration
Configure company SSO with Google
Google SSO setup
Google sign-in when the task is company SSO configuration
Add extra verification during sign-in
MFA
MFA as the main sign-in method
Control password requirements
Password policy
manual password rules outside account settings
Authorize API requests
Application tokens
application tokens for regular user sign-in
Manage automated access
Integrations and API access
password sharing or manual sign-in for API flows
After you choose a method, use the scenarios below to confirm the correct flow.
Typical scenarios
Sign in a personal account
Goal: Access a personal DocStudio account without company-managed SSO.
Use:
email and password
Google sign-in
Microsoft / Azure sign-in
Apple sign-in
Do not use:
SSO when the user does not belong to a company SSO setup
application tokens for interface access
admin SSO setup instructions for a personal sign-in issue
Go to:
Sign in as a corporate user
Goal: Access a company workspace with the configured company method.
Use:
email and password, if the company allows it
Google sign-in, if the company uses it
Microsoft / Azure sign-in, if the company uses it
SSO, if the company requires it
Do not use:
personal account registration when the user must access company data
application tokens for interface access
password reset as the only fix when the company requires SSO
Go to:
Choose the correct invitation flow
Goal: Start the correct first login flow from an invitation.
Use:
the standard sign-in flow, if the invite is for regular account access
the company SSO flow, if the invite is tied to company SSO
the company-configured provider flow, if the company uses it
Do not use:
password reset before you confirm the expected access method
personal registration when the invite is for a company workspace
application tokens for first login
Go to:
Sign in with a third-party provider
Goal: Sign in through Google, Microsoft / Azure, or Apple.
Use:
Google sign-in
Microsoft / Azure sign-in
Apple sign-in
Do not use:
SSO setup instructions when the user only needs a provider button
password reset when the problem is with the provider flow
application tokens for user sign-in
Go to:
Sign in through SSO
Goal: Access DocStudio through company-managed authentication.
Use:
SSO on the sign-in page
the SSO invitation flow
the company identity provider flow
Do not use:
Google, Microsoft / Azure, or Apple sign-in when the company requires SSO
application tokens for interactive sign-in
personal account registration after an SSO invitation
Go to:
Configure Azure SSO for a company
Goal: Connect DocStudio to Azure-based company identity management.
Use:
Azure SSO SAML 2.0
Azure SSO OAuth 2.0
SSO provider configuration
Do not use:
Microsoft / Azure sign-in when the task is company SSO setup
personal user sign-in guidance for admin setup
application tokens for user authentication
Go to:
Configure Google SSO for a company
Goal: Connect DocStudio to Google-based company identity management.
Use:
Google SSO setup
SSO provider configuration
Do not use:
Google sign-in when the task is company SSO setup
email and password when company policy requires SSO
application tokens for user sign-in
Go to:
Require additional verification with MFA
Goal: Add an extra verification step to sign-in.
Use:
MFA
Do not use:
MFA as the main sign-in method
MFA instead of email and password, provider sign-in, or SSO
application tokens as a replacement for MFA
Go to:
Authorize API requests
Goal: Authorize API requests without sharing a user password.
Use:
application tokens
integrations and API access
Do not use:
application tokens for regular interface sign-in
user password sharing for integrations
SSO setup as a replacement for API authorization
Go to:
User sign-in methods
Email and password
Use email and password when a user signs in with standard DocStudio credentials.
When to use: Use this method when the user has a DocStudio account and wants to sign in directly.
Best for:
standard sign-in
users who do not use a provider sign-in method
users who do not need company SSO
Do not use this when:
the user signs in with Google, Microsoft / Azure, or Apple
the company requires SSO
the task is API access
Go to:
Google sign-in
Use Google sign-in when the user wants to access DocStudio through a Google account.
When to use: Use this method when the sign-in page shows the Google button and the user’s DocStudio access is connected to a Google account.
Best for:
users who use Google as their sign-in provider
users who do not want a separate DocStudio password
organizations that allow Google-based access
Do not use this when:
the company requires a separate SSO flow
the user needs Microsoft / Azure, Apple, or email and password
the task is API access
Go to:
Microsoft / Azure sign-in
Use Microsoft / Azure sign-in when the user wants to access DocStudio through a Microsoft or Azure account.
When to use: Use this method when the sign-in page shows the Microsoft button and the user’s DocStudio access is connected to a Microsoft or Azure account.
Best for:
users who use Microsoft accounts
users whose company allows Microsoft / Azure sign-in
users who do not want a separate DocStudio password
Do not use this when:
the company requires a separate SSO flow
the task is to configure Azure SSO
the task is API access
Go to:
Apple sign-in
Use Apple sign-in when the user wants to access DocStudio through Apple ID.
When to use: Use this method when the sign-in page shows the Apple button and the user’s DocStudio access is connected to Apple ID.
Best for:
users who use Apple ID as their sign-in provider
users who access the profile through Apple sign-in
Do not use this when:
the user must access DocStudio through company SSO
the user selected Hide My Email and DocStudio cannot complete the flow
the task is API access
Go to:
SSO
Use SSO when the company requires users to access DocStudio through a corporate identity provider.
When to use: Use this method when the user received an SSO invitation or the company requires SSO for access.
Best for:
corporate users
company-managed access
centralized authentication
admin-controlled security policies
Do not use this when:
the user only needs Google, Microsoft / Azure, or Apple sign-in
the user has only a personal account
the task is API access through application tokens
Go to:
Company SSO setup
Azure SSO setup
Use Azure SSO setup when a company needs to connect DocStudio to Azure-based identity management.
When to use: Use Azure SSO setup when an admin or technical team configures company-level SSO.
Best for:
companies that use Azure or Microsoft identity services
corporate users who must authenticate through company identity rules
centralized identity management
Do not use this when:
a user only needs Microsoft / Azure sign-in on the sign-in page
a personal user just needs to sign in
the task is API access
Go to:
Google SSO setup
Use Google SSO setup when a company needs to connect DocStudio to Google-based identity management.
When to use: Use Google SSO setup when an admin or technical team configures company-level SSO.
Best for:
companies that use Google Workspace or Google identity services
corporate users who must authenticate through company identity rules
centralized identity management
Do not use this when:
a user only needs Google sign-in on the sign-in page
a personal user just needs to sign in
the task is API access
Go to:
Security settings
MFA
Use MFA when sign-in requires an additional verification step.
When to use: Use MFA to add extra protection to sign-in.
Best for:
stronger account protection
corporate accounts with stricter security requirements
sign-in flows that need an extra check
Do not use this when:
you need to choose the main sign-in method
you need API access
you need to configure an SSO provider connection
Go to:
Password policy
Use password policy when a company needs to control password requirements.
When to use: Use password policy when security rules must define password complexity, expiration, or reuse behavior.
Best for:
corporate accounts
admin-managed security settings
organizations with stricter password requirements
Do not use this when:
the issue is SSO provider setup
the user signs in only through a provider-based flow
the task is API access
Go to:
API access
Application tokens
Use application tokens when API requests or third-party integrations need authorization.
When to use: Use application tokens for API access, not for regular user sign-in.
Best for:
developers
API requests
third-party integrations
automated processes
Do not use this when:
a user needs to sign in to the DocStudio interface
a company needs SSO setup
a user forgot their password
the user needs MFA for interactive sign-in
Go to:
Common mistakes
Avoid these mistakes when you choose an access method:
Using Google sign-in when the task is Google SSO setup.
Using Microsoft / Azure sign-in when the task is Azure SSO setup.
Using application tokens for regular user sign-in.
Using MFA as the main sign-in method.
Using email and password when the company requires SSO.
Using SSO setup instructions when the user only needs to click Google, Microsoft / Azure, or Apple on the sign-in page.
Using a personal access flow for a corporate user who received an SSO invitation.
Resetting the password when the real issue is company SSO configuration.
Configuring SSO when the task only needs API access through an application token.
Using user passwords in integrations instead of application tokens.
Quick decision guide
Use these rules to choose faster:
If the user has a standard DocStudio account, use email and password.
If the user signs in through Google, use Google sign-in.
If the user signs in through Microsoft or Azure, use Microsoft / Azure sign-in.
If the user signs in through Apple ID, use Apple sign-in.
If the company manages access through a corporate identity provider, use SSO.
If the company uses Azure for identity management, configure Azure SSO setup.
If the company uses Google for identity management, configure Google SSO setup.
If sign-in needs an extra verification step, use MFA.
If the task is API access, use application tokens.
If password rules must be stricter, configure password policy.
Useful links
User sign-in
Company SSO setup
Security settings
API access
Last updated