Skip to content
Product block

Enterprise SSO Split

What SSO actually covers, written for the person who has to configure it rather than the person who asked for it.

155 linesNo dependenciesAdded 9 Sept 2026
  • sso
  • saml
  • scim
  • enterprise
  • auth

What's included

  • components/sso-enterprise-split.tsx
  • No runtime dependencies

Works with

  • React
  • Next.js
  • Tailwind CSS
  • TypeScript

npx hoverlab add sso-enterprise-split

Or over MCP, from your editor's agent — no account needed.

License

Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.

Was this useful?

Start a page with this section — add more, order them, and leave with the page source.

Preview

Single sign-on

Your directory, your rules

SSO on a pricing page is one word. To the person configuring it, it is four separate features that vendors bundle inconsistently — so this names them.

  • SAML 2.0 and OIDCBoth, against any provider. Okta, Entra and Google are documented step by step.
  • SCIM provisioningUsers appear and disappear with your directory. Deprovisioning is the half that matters.
  • Enforced, not optionalPassword login can be switched off per domain, so a bypass is not one setting away.
  • Included, not an upsellOn every paid plan. Charging for the control that makes offboarding safe is a security tax.

Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.

Source

components/sso-enterprise-split.tsx
/**
 * <SsoEnterpriseSplit> — What SSO actually covers, written for the person who has to configure it rather than the person who asked for it.
 *
 * On a pricing page SSO is one word. To the person configuring it, it is
 * four features that vendors bundle inconsistently, and the layout problem
 * is that the reader who cares cannot tell from a checkmark which four they
 * are getting.
 *
 * The obvious wrong answer is a checkmark in a comparison table. It cannot
 * distinguish SAML-only from SAML plus SCIM, and that distinction is the
 * entire difference between a working offboarding process and a manual one.
 *
 * So the four points are named separately, and the second is the one that
 * matters most: deprovisioning. Provisioning users automatically is a
 * convenience; removing them automatically when someone leaves the company
 * is the security control, and it is the half that is usually missing.
 *
 * The fourth point is a position rather than a feature. Charging for the
 * control that makes offboarding safe is a security tax, and saying that on
 * the page is a commitment the pricing table then has to honour.
 *
 * Accessibility: the tick is an inline `<svg>` marked `aria-hidden` with
 * `fill="currentColor"`, so it inherits the text colour and is skipped
 * entirely rather than announced four times as nothing. The section takes
 * its accessible name from the heading via `aria-labelledby`, and the points
 * are a real `<ul>` so their number is announced before they are read.
 *
 * The right-hand panel is drawn rather than an image — nothing to host, no
 * layout shift, and it follows the theme. Pass `media` to replace it with a
 * real screenshot of the provider configuration screen, which is the one
 * place a screenshot beats a drawing here.
 */

import * as React from 'react'

export interface SsoEnterpriseSplitPoint {
  label: string
  detail?: string
}

export interface SsoEnterpriseSplitProps {
  eyebrow?: string
  heading?: string
  intro?: string
  points?: SsoEnterpriseSplitPoint[]
  /** Your own visual. Omit for the drawn panel, which needs no asset. */
  media?: React.ReactNode
  className?: string
}

const POINTS: SsoEnterpriseSplitPoint[] = [
  { label: "SAML 2.0 and OIDC", detail: "Both, against any provider. Okta, Entra and Google are documented step by step." },
  { label: "SCIM provisioning", detail: "Users appear and disappear with your directory. Deprovisioning is the half that matters." },
  { label: "Enforced, not optional", detail: "Password login can be switched off per domain, so a bypass is not one setting away." },
  { label: "Included, not an upsell", detail: "On every paid plan. Charging for the control that makes offboarding safe is a security tax." },
]

/*
  Per-instance id, hashed from props that differ between instances.

  A literal id is a latent duplicate the moment this block is rendered
  twice on one document -- two pages on a catalog hub, or one page using
  the section twice. `aria-labelledby` pointing at a duplicated id resolves
  to whichever element comes first, so the second copy is announced with
  the first copy's label. Server component, so no `useId`: hashing props
  gives each instance its own target and stays stable across server and
  client renders in a way a counter would not.
*/
function instanceId(...parts: (string | undefined)[]): string {
  const text = parts.filter(Boolean).join('|')
  let hash = 0
  for (let i = 0; i < text.length; i++) hash = (Math.imul(hash, 31) + text.charCodeAt(i)) | 0
  return (hash >>> 0).toString(36).slice(0, 6)
}

export function SsoEnterpriseSplit({
  eyebrow = "Single sign-on",
  heading = "Your directory, your rules",
  intro = "SSO on a pricing page is one word. To the person configuring it, it is four separate features that vendors bundle inconsistently — so this names them.",
  points = POINTS,
  media,
  className,
}: SsoEnterpriseSplitProps) {
  const uid = instanceId(heading)

  return (
    <section
      aria-labelledby={`sso-enterprise-split-heading-${uid}`}
      className={`w-full bg-background px-6 py-16 sm:py-24 ${className ?? ''}`}
    >
      <div className="mx-auto grid max-w-6xl items-center gap-12 lg:grid-cols-2">
        <div>
          <p className="text-sm font-medium text-primary">{eyebrow}</p>
          <h2
            id={`sso-enterprise-split-heading-${uid}`}
            className="mt-2 text-3xl font-semibold tracking-tight text-foreground sm:text-4xl"
          >
            {heading}
          </h2>
          <p className="mt-4 text-base text-muted-foreground">{intro}</p>

          <ul className="mt-8 space-y-4">
            {points.map((point) => (
              <li key={point.label} className="flex gap-3">
                {/*
                  currentColor, not a token in a raw colour function. These
                  are complete oklch() values, so hsl(var(--primary)) is not
                  a colour and the declaration is dropped silently.
                */}
                <svg
                  aria-hidden="true"
                  viewBox="0 0 20 20"
                  className="mt-0.5 size-5 shrink-0 text-primary"
                  fill="currentColor"
                >
                  <path d="M16.7 5.3a1 1 0 0 1 0 1.4l-7.5 7.5a1 1 0 0 1-1.4 0L3.3 9.7a1 1 0 1 1 1.4-1.4l3.8 3.8 6.8-6.8a1 1 0 0 1 1.4 0Z" />
                </svg>
                <span>
                  <span className="block text-sm font-medium text-foreground">{point.label}</span>
                  {point.detail ? (
                    <span className="mt-0.5 block text-sm text-muted-foreground">
                      {point.detail}
                    </span>
                  ) : null}
                </span>
              </li>
            ))}
          </ul>
        </div>

        {/*
          The drawn panel rather than an <img>. No asset to host, no layout
          shift while it loads, and it themes with the rest of the page —
          which a screenshot of somebody's light-mode dashboard does not.
        */}
        <div className="rounded-xl border border-border bg-card p-6 shadow-sm">
          {media ?? (
            <div aria-hidden="true" className="space-y-3">
              <div className="h-3 w-1/3 rounded bg-primary/30 border border-transparent" />
              <div className="h-24 rounded-lg bg-muted border border-transparent" />
              <div className="grid grid-cols-3 gap-3">
                <div className="h-14 rounded-lg bg-muted border border-transparent" />
                <div className="h-14 rounded-lg bg-muted border border-transparent" />
                <div className="h-14 rounded-lg bg-muted border border-transparent" />
              </div>
              <div className="h-3 w-2/3 rounded bg-muted border border-transparent" />
              <div className="h-3 w-1/2 rounded bg-muted border border-transparent" />
            </div>
          )}
        </div>
      </div>
    </section>
  )
}

Before you paste

  • Styling is Tailwind utility classes on semantic tokens (bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.
  • Nothing to install. No component library, no icon package.
  • Every prop has a default, so it renders standalone before you wire it up.

Where it goes

Drop it at components/sso-enterprise-split.tsx and import it where you need the section:

import { SsoEnterpriseSplit } from '@/components/sso-enterprise-split'

Customize

2 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.

Props

Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.

PropTypeDefault
eyebrowstring"Single sign-on"
headingstring"Your directory, your rules"
introstring—
pointsSsoEnterpriseSplitPoint[]POINTS
mediaYour own visual. Omit for the drawn panel, which needs no asset.React.ReactNode—
classNamestring—

Not using React?

The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.

sso-enterprise-split.html
<!--
  Enterprise SSO Split — markup from the Hoverlab catalog.

  This is the block rendered once to HTML and wrapped as a component
  file. It is not a port of the React source: the Tailwind classes carry
  the design, which is the part that took the work, and they are the same
  in every framework.

  This block has no interactive behaviour, so nothing is missing.
-->
<section aria-labelledby="sso-enterprise-split-heading-1d694p" class="w-full bg-background px-6 py-16 sm:py-24 ">
  <div class="mx-auto grid max-w-6xl items-center gap-12 lg:grid-cols-2">
    <div>
      <p class="text-sm font-medium text-primary">Single sign-on</p>
      <h2 id="sso-enterprise-split-heading-1d694p" class="mt-2 text-3xl font-semibold tracking-tight text-foreground sm:text-4xl">Your directory, your rules</h2>
      <p class="mt-4 text-base text-muted-foreground">SSO on a pricing page is one word. To the person configuring it, it is four separate features that vendors bundle inconsistently — so this names them.</p>
      <ul class="mt-8 space-y-4">
        <li class="flex gap-3">
          <svg aria-hidden="true" viewBox="0 0 20 20" class="mt-0.5 size-5 shrink-0 text-primary" fill="currentColor">
            <path d="M16.7 5.3a1 1 0 0 1 0 1.4l-7.5 7.5a1 1 0 0 1-1.4 0L3.3 9.7a1 1 0 1 1 1.4-1.4l3.8 3.8 6.8-6.8a1 1 0 0 1 1.4 0Z"></path>
          </svg>
          <span>
            <span class="block text-sm font-medium text-foreground">SAML 2.0 and OIDC</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Both, against any provider. Okta, Entra and Google are documented step by step.</span>
          </span>
        </li>
        <li class="flex gap-3">
          <svg aria-hidden="true" viewBox="0 0 20 20" class="mt-0.5 size-5 shrink-0 text-primary" fill="currentColor">
            <path d="M16.7 5.3a1 1 0 0 1 0 1.4l-7.5 7.5a1 1 0 0 1-1.4 0L3.3 9.7a1 1 0 1 1 1.4-1.4l3.8 3.8 6.8-6.8a1 1 0 0 1 1.4 0Z"></path>
          </svg>
          <span>
            <span class="block text-sm font-medium text-foreground">SCIM provisioning</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Users appear and disappear with your directory. Deprovisioning is the half that matters.</span>
          </span>
        </li>
        <li class="flex gap-3">
          <svg aria-hidden="true" viewBox="0 0 20 20" class="mt-0.5 size-5 shrink-0 text-primary" fill="currentColor">
            <path d="M16.7 5.3a1 1 0 0 1 0 1.4l-7.5 7.5a1 1 0 0 1-1.4 0L3.3 9.7a1 1 0 1 1 1.4-1.4l3.8 3.8 6.8-6.8a1 1 0 0 1 1.4 0Z"></path>
          </svg>
          <span>
            <span class="block text-sm font-medium text-foreground">Enforced, not optional</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">Password login can be switched off per domain, so a bypass is not one setting away.</span>
          </span>
        </li>
        <li class="flex gap-3">
          <svg aria-hidden="true" viewBox="0 0 20 20" class="mt-0.5 size-5 shrink-0 text-primary" fill="currentColor">
            <path d="M16.7 5.3a1 1 0 0 1 0 1.4l-7.5 7.5a1 1 0 0 1-1.4 0L3.3 9.7a1 1 0 1 1 1.4-1.4l3.8 3.8 6.8-6.8a1 1 0 0 1 1.4 0Z"></path>
          </svg>
          <span>
            <span class="block text-sm font-medium text-foreground">Included, not an upsell</span>
            <span class="mt-0.5 block text-sm text-muted-foreground">On every paid plan. Charging for the control that makes offboarding safe is a security tax.</span>
          </span>
        </li>
      </ul>
    </div>
    <div class="rounded-xl border border-border bg-card p-6 shadow-sm">
      <div aria-hidden="true" class="space-y-3">
        <div class="h-3 w-1/3 rounded bg-primary/30 border border-transparent"></div>
        <div class="h-24 rounded-lg bg-muted border border-transparent"></div>
        <div class="grid grid-cols-3 gap-3">
          <div class="h-14 rounded-lg bg-muted border border-transparent"></div>
          <div class="h-14 rounded-lg bg-muted border border-transparent"></div>
          <div class="h-14 rounded-lg bg-muted border border-transparent"></div>
        </div>
        <div class="h-3 w-2/3 rounded bg-muted border border-transparent"></div>
        <div class="h-3 w-1/2 rounded bg-muted border border-transparent"></div>
      </div>
    </div>
  </div>
</section>
  • This is rendered HTML, not a translation of the React source. The Tailwind classes carry the design and work in any framework.
  • It is one frame: the component in its initial state, with no props applied beyond the defaults.
  • Requires Tailwind, and the design tokens the classes reference (bg-card, text-muted-foreground, and so on). The template ZIPs ship a globals.css that defines them.

What each framework gets across the whole catalog — effects convert properly; this rung is markup.

For AI

The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.

See the prompt

Used in these pages

Want the whole screen instead of this one section? Open a page and copy it entire.

8 more blocks in Authentication

All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.

Browse Authentication

Shipping one commercially

Copying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.

  • A commercial licence for everything in the catalog
  • Unlimited bundle exports, in Vue, Svelte and Tailwind
  • One payment — no subscription, nothing to renew
Pro — $79 once

More Authentication blocks

View category
Open the full page for this block

Split Signup With Proof

Registration form beside a testimonial panel, with live password rules and a proof column that drops rather than stacks on mobile.

Authentication205 lines1 dep
Open the full page for this block

One-Time Code Input

Six-box OTP entry that handles paste, backspace, arrow keys and iOS SMS autofill — the parts hand-rolled versions always miss.

Authentication184 lines1 dep
Open the full page for this block

New Password With Strength Meter

Set-a-new-password form with a four-step strength meter, confirm matching and errors announced rather than only coloured.

Authentication179 lines1 dep
Open the full page for this block

Two-Factor Challenge

Authenticator-code prompt with a backup-code escape hatch and an opt-in trusted-device checkbox that is off by default.

Authentication148 lines1 dep
Open the full page for this block

Email-First SSO Sign-In

Email first, then whatever that domain uses. The password field is absent rather than disabled when SSO is enforced, the button names the company it redirects to, and a personal address is a normal answer instead of an error.

Authentication257 lines1 dep
Open the full page for this block

Magic Link Sign In

Passwordless sign-in that says what will land in the inbox and how long it lasts, before the address is typed.

Authentication176 linesNo deps