SilentChat

How do I enable SAML SSO?

Last updated: September 9, 2026

SAML 2.0 Single Sign-On

SAML SSO is included in the Enterprise plan. With SSO, team members log in via your Identity Provider (Okta, Azure AD, Google Workspace, ...) — no second password hygiene anymore.

Setup Steps

  1. In the Dashboard: Settings → Security → SAML SSO → "Start Setup"
  2. Copy Service Provider Details:
    • ACS URL: https://api.silentchat.de/api/v1/auth/saml/acs/DEINE_TENANT_ID
    • Entity ID: https://app.silentchat.de/saml/DEINE_TENANT_ID
    • Name ID Format: EmailAddress
  3. At the Identity Provider: Create a new SAML application with the above values. Attribute Mapping: email, firstName, lastName.
  4. Import Metadata into the Dashboard: Insert IdP Metadata XML or URL — we automatically parse the Entity-ID + Cert.
  5. Test: "Test SSO Login" goes through the round trip; if there are errors, the dashboard shows the full SAML response payload for debugging.

Just-in-Time Provisioning

Enabled by default: Users who are not yet in the tenant are automatically created with the default role (Agent) on their first SSO login. You can override this per tenant under "Default Role for JIT".

Domain Restriction

Settings → Security → "Allowed Email Domains": enter comma-separated (e.g., acme.com, acme.de). Users with other email domains are rejected — even if the IdP sends them back.

How do I enable SAML SSO? — Help Center — SilentChat | SilentChat