---
title: Integrations
sidebar:
  label: Overview
description: Keep your user list and groups in sync with Google Workspace, Microsoft Entra ID, or Okta.
---

:::info
The **Apps** tab is part of the next console release. In that release, the left-menu item **Extensions** becomes **Integrations**, with an **Apps** tab (these integrations) and an **Extensions** tab (everything else in this section).
:::

An **integration** connects Surface to another company service. The first group is **Directory & identity**: syncing users and groups from your identity provider so the console's Users page stays current.

Each app is a card with a status: **Connected**, **Not connected**, or **Coming soon**.

| App | How it works | Guide |
| --- | --- | --- |
| **Google Workspace** | You sign in to Google once. Surface then reads group membership on a schedule | [Connect Google Workspace](/surface/extensions/integrations/google-workspace) |
| **Microsoft Entra ID** | Entra pushes users and groups to Surface over SCIM | [Connect Entra ID or Okta](/surface/extensions/integrations/entra-okta) |
| **Okta** | Okta pushes users and groups to Surface over SCIM | [Connect Entra ID or Okta](/surface/extensions/integrations/entra-okta) |
| **Claude Enterprise**, **Codex Enterprise** | Bring usage and members from those products into Surface | Coming soon |

SCIM is the standard identity providers use to push user lists to other services.

## Disconnecting

Click **Disconnect** on a card and confirm.

:::warning
Disconnecting removes the connection **and the users and groups it created**. Any token you pasted into Entra or Okta stops working. Reconnecting means running the setup again with a new token.
:::

## Single sign-on

Signing in to the console is email-first: a person types their work email and is sent to the right sign-in page. Setting up your company's SSO is done with SuperAlign during onboarding.
