WiseStamp for IT › Exchange › Step 6 of 12 — SSO (SAML)
Plan requirement: Platform or Enterprise.
Note: pricing lists SSO under Platform and Enterprise, while the "Account Login Methods" article lists "Legacy Enterprise, Advance, and Enterprise." These are not in conflict — Advance is the previous commercial name for the Platform plan. SSO is available on Platform (formerly Advance) and Enterprise.
Scope: SSO governs admin sign-in to WiseStamp, not signature deployment. Employees do not log into WiseStamp; they use the Employee Hub. SSO is optional.
Who does what
Step | Owner |
Create the SSO domain in WiseStamp; issue Provider ID | WiseStamp support |
Configure the WiseStamp app in your IdP | You (IT) |
Send IdP SAML metadata to WiseStamp | You (IT) |
Apply metadata / finalize | WiseStamp support |
Contact WiseStamp support first to create the SSO domain and obtain your Provider ID (used as RelayState).
SAML endpoints (WiseStamp service provider)
Field | Value |
ACS URL / Single Sign-On URL | |
SP Entity ID / Audience URI | |
Default RelayState | Your Provider ID |
Name ID format | EmailAddress |
The SP Entity ID / Audience URI differs by identity provider — confirm the exact value for Microsoft Entra ID with WiseStamp support.
Procedure — Microsoft Entra ID
The knowledge base documents click-paths for Okta, Google Workspace, and OneLogin, but not an Entra ID-specific walkthrough. The steps below are the standard Entra non-gallery SAML flow mapped to WiseStamp’s documented SP endpoints. Validate against your tenant’s current admin center labels.
Sign in to the Microsoft Entra admin center.
Identity > Applications > Enterprise applications > New application > Create your own application.
Name WiseStamp, choose Non-gallery, create.
Open the app > Single sign-on > SAML.
Basic SAML Configuration:
Identifier (Entity ID): the SP Entity ID above.
Reply URL (ACS): https://webapp.wisestamp.com/api/saml/callback
Relay State: your Provider ID.
Confirm the Name ID claim is the user’s email (EmailAddress).
Assign users/groups under Users and groups.
Download Federation Metadata XML and send it to WiseStamp support.
Validation
After WiseStamp applies metadata, go to https://webapp.wisestamp.com/login.
Initiate SSO; confirm redirect to the IdP and back, landing authenticated.
Confirm an assigned user can sign in and an unassigned user is denied.
Other supported IdPs (reference)
Documented click-paths exist for Okta, Google Workspace, and OneLogin, using the same ACS URL and Provider ID/RelayState pattern.