How do I enable SAML SSO?
Last updated: May 15, 2026
SAML 2.0 Single Sign-On
SAML SSO is part of the Enterprise plan. With SSO your team members sign in through your identity provider (Okta, Azure AD, Google Workspace, ...) — no more separate password hygiene.
Setup steps
- In the dashboard: Settings → Security → SAML SSO → "Start setup"
- Copy service provider details:
- ACS URL:
https://api.silentchat.de/api/v1/auth/saml/acs/YOUR_TENANT_ID - Entity ID:
https://app.silentchat.de/saml/YOUR_TENANT_ID - Name ID Format: EmailAddress
- ACS URL:
- In the identity provider: create a new SAML application with the values above. Attribute mapping: email, firstName, lastName.
- Return metadata to the dashboard: paste the IdP metadata XML or URL — we parse entity ID + cert automatically.
- Test: "Test SSO login" runs the full round-trip; on failure the dashboard displays the SAML response payload for debugging.
Just-in-time provisioning
Enabled by default: users who are not yet in the tenant get created with the default role (Agent) on first SSO login. Override per tenant under "Default role for JIT".
Domain restriction
Settings → Security → "Allowed email domains": comma-separated (e.g. acme.com, acme.de). Users with other email domains are rejected — even when the IdP returns them.