Skip to content

Identity setup guides

Set from Admin → Identity. Every guide below is self-serve — there is no support ticket required.

Google Workspace sign-in

Once Google sign-in is enabled for your organization, anyone with a work Google account can continue straight to Mucho Gusto — no separate password to create. This is a standard Google OAuth connection, the same kind of "Sign in with Google" button most apps offer — nothing needs to be configured in Google Admin for it to work.

To make it feel automatic for your whole team, pair it with a verified email domain below — that's what makes a work Google account land a new hire directly in your org, with no invite.

Microsoft 365 sign-in

The same idea as Google, for a Microsoft 365 / Entra ID work account. This is Microsoft's standard OAuth sign-in — a genuine, honest "use your work login" answer for a Microsoft shop. Nothing needs to be configured in Microsoft Admin Center for it to work.

Verifying your email domain

From Admin → Identity → Verified email domains:

  1. Enter your organization's domain (e.g. acme.com) and click Add Domain.
  2. Publish the TXT record shown at your DNS provider — the record name starts with _muchogusto-verify. and the value starts with mg-verify=.
  3. Click Verify. DNS changes can take a few minutes (occasionally longer) to propagate — if verification doesn't succeed right away, wait a bit and try again.

Once verified, turn on Auto-join for the domain. From then on, anyone who signs in with a verified Google or Microsoft work email on that domain lands directly in your organization — no invite needed. A domain belongs to exactly one organization; a free email provider (Gmail, Outlook.com, etc.) can never be verified as an organization domain, no matter what DNS record is published.

SCIM provisioning

From Admin → Identity → SCIM provisioning, mint a token and copy the base URL shown. Paste both into your identity provider's SCIM connector settings to have it automatically create and remove members as people join and leave.

The token is shown in full exactly once, at mint time — store it in your identity provider immediately. If you ever suspect it's been exposed, rotate it from the same screen; the old token stops working the moment you do. Token minting is only available from the web admin console, not the iOS app, so a one-time secret is never displayed on a phone.

Questions about any of this? [email protected].