> ## Documentation Index
> Fetch the complete documentation index at: https://docs.prophecy.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication options

> Use your identity provider to sign in to Prophecy

<Callout icon="/images/icon.png" color="#FFC107">
  Custom authentication is available for the [Enterprise and Express Editions](/administration/platform/editions) only.
</Callout>

When logging in to Prophecy, you can either credentials managed directly by Prophecy, or set up SSO. Prophecy integrates with multiple identity providers to let you log in using your external credentials. You can configure SSO under **Settings > SSO**.

Only [Prophecy cluster admins](/administration/management/users/access/role-based-access) have permission to view and edit SSO settings.

## Prophecy-managed authentication

By default, Prophecy uses **Prophecy Managed** authentication. This option requires no external identity provider.

* User accounts are created and managed inside Prophecy.
* Passwords are stored securely within Prophecy.
* Use this mode if you don't have an external SSO requirement.

If you set up SSO after creating users in Prophecy, sign-ins will map to existing users if the sign-in email matches the user email in Prophecy.

## Fabric OAuth

To set up OAuth for fabric connection authentication, see [OAuth app registrations](/administration/management/cluster-admin-settings/oauth-setup).
