Set up enterprise-managed connections for Notion MCP

In this help doc

Learn how to turn on enterprise-managed connections for Notion MCP and manage who can use it.

Jump to FAQs

Enterprise-managed connections let your IT team manage how third-party AI tools like Claude connect to Notion, all in one place. Instead of each person approving the connection themselves, your Okta admin sets it up once for everyone. Notion still checks what each person can access and your workspace's admin settings on every request. The connection is built on Okta Cross App Access (XAA).

  • This is available for workspaces on the Enterprise plan.

  • Your company must use Okta to sign in to Notion, and your Notion SAML single sign-on (SSO) needs to run through that same Okta account.

  • The AI tool you’re connecting needs to support enterprise-managed connections.

    • Enterprise-managed connections only work with apps that support Okta Cross App Access (XAA). If an app doesn’t support this, each person will still need to connect Notion the usual way and approve access themselves. This is currently available for Claude on Enterprise plans when you use organization connectors.

  • You’ll need an Okta admin, a Notion organization owner (or workspace owner if you’re not using organizations), and a Claude admin to complete setup.

Notion MCP normally asks each person to approve the connection between their app and their Notion account. With enterprise-managed connections, that approval step goes away for your team:

  1. A member signs in to Claude with your company's Okta SSO.

  2. When Claude needs Notion, Okta checks the rules your admin set and confirms the connection is allowed.

  3. Notion checks that the request really came from Okta, matches the member to their Notion account, and gives Claude the same access to Notion that the member already has. Nothing more.

Members won't see a Notion approval screen. Each connection stays active for up to eight hours at a time, and Notion checks your workspace's settings on every request. If you remove someone's access in Okta, they won't be able to start a new connection, but a connection that's already active can keep working until it expires. To stop someone's access right away, disconnect them in Notion.

Setting up an enterprise-managed connection has three steps:

  • Connect the apps in Okta

  • Turn it on in Notion

  • Turn on the connector in Claude

An Okta admin can follow the steps below to connect Claude and Notion MCP:

  1. In the Okta Admin Console, make sure SSO is turned on for both your Claude and Notion apps, and that Cross App Access is available.

  2. Add the connection between Claude and Notion MCP, and assign the users or groups it should cover.

  3. Note your Okta org's issuer URL (for example https://acme.okta.com). You'll enter it in Notion next.

For details, see Configure Cross App Access in Okta's help center.

A Notion organization owner (or workspace owner, if you're not using organizations) can follow the steps below to connect your Okta account to your Notion workspace:

  1. Go to SettingsIdentityEnterprise-managed connections. If SAML is managed by a Notion organization, open the linked organization console.

  2. Turn on enterprise-managed connections and confirm your Okta issuer URL. It must match the Okta address that runs your Notion SAML SSO.

  3. Choose the one workspace this connection manages, then select Turn on.

A Claude admin can follow the steps below to add Notion as an organization connector:

  1. In Claude's admin settings, go to Connectors and add the Notion connector (https://mcp.notion.com/mcp).

  2. Turn on Enterprise managed authentication for the connector.

  3. Run the connection test. When all checks pass, members can use Notion in Claude right away.

  • Turn it off any time. Turn off the connection in Enterprise-managed connections. Notion blocks any new requests and disconnects members who were connected this way.

  • Remove one person. Remove them from the connection in Okta so they can't reconnect. To end an active connection right away, disconnect the member from the connection's member list in Notion.

  • See who's connected. Managed connections appear in your workspace's connected AI apps list, labeled as managed by your identity provider.

  • Audit everything. Each member's first managed connection is recorded in the workspace audit log and sent to your security monitoring tools if you've set up the audit log event stream.


FAQs

Do members have to do anything?

No. If they're covered by your Okta policy, Notion tools appear in the external AI app automatically after they sign in with SSO.

What can the external AI app access once connected?

Exactly what each member can access in Notion, nothing more. Enterprise-managed connections change how the connection is approved, not what it can access. Your existing Notion MCP admin controls, like the allowed AI apps list, still apply.

What happens when someone leaves the company?

Remove them in Okta as usual, and they won't be able to start new connections. A connection that's already active can keep working for up to eight hours, so disconnect the member in Notion if their access needs to stop sooner.

We already use Notion MCP with individual connections. What changes?

Members covered by the managed connection stop seeing approval prompts for Claude. Individual connections from other AI tools keep working as before.

Our Notion SSO doesn't run on Okta. Can we use this?

Not yet. Right now, Okta must be the identity provider that runs your Notion SAML SSO, because Cross App Access is currently an Okta capability. Support for more setups is planned.

Which AI tools are supported?

Claude organization connectors are supported. Support for more AI tools is coming.


Give Feedback

Was this resource helpful?