LettermintLettermint
  • Knowledge base
  • Community
  • Changelog
  • Support
  • Documentation
  • Sending API
  • Team API
Getting started
Guides
Platform
    Projects & Routes
    Emails
    Domains
    Webhooks
    Teams
      Team API
      RolesTeam membersAccount and team security
      SSO
      SCIMSpend Limits
    Onboarding
Resources
Teams

Account and team security

Account and team security

Lettermint supports account-level and team-level controls for securing access to your email infrastructure.

Account security

Users can secure their own account with passkeys and connected OAuth providers.

Passkey and OAuth providers screen.

Team MFA enforcement

Members with Manage team security can require team members to use multi-factor authentication before accessing team resources.

Team MFA enforcement settings.

Enterprise identity

Use SSO to route managed users through your identity provider, and SCIM to provision and deprovision users.

SSO

Configure SAML or OIDC sign-in.

SCIM

Provision users and groups.

Managing SSO providers, SCIM tokens, role mappings, and team MFA enforcement requires Manage team security. Reading recorded security events requires View audit log.

Token security

  • Use Project API tokens only for sending.
  • Use Team API tokens only for management automation.
  • Create one token per integration.
  • Add IP allowlists for tokens used from stable outbound IP addresses.
  • Rotate or revoke tokens when ownership changes.
  • Never expose tokens in client-side code.

Next steps

  • Team API tokens
  • Roles
  • Project API tokens
  • SSO
  • SCIM
Last modified on July 19, 2026
Team membersSSO
On this page
  • Account security
  • Team MFA enforcement
  • Enterprise identity
  • Token security
  • Next steps