Skip to main content
Available on the Enterprise plan.

Overview

SAML SSO lets your team log in to Wave Connect through your organization’s identity provider (IdP). Instead of managing a separate Wave Connect password, users authenticate with the same credentials they use for everything else. Wave Connect supports SAML 2.0 and works with any standards-compliant identity provider, including Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, and Ping Identity. Wave Connect also supports OpenID Connect (OIDC). Contact support@wavecnct.com if you need a guide.

How It Works

There are two login paths depending on whether the user already has a Wave Connect account.
Users can also initiate SSO directly with this URL: https://app.wavecnct.com/auth/sso?org=YOUR_ORG_SLUG. Replace YOUR_ORG_SLUG with your organization slug, found in your organization settings.
No account yet: The user clicks Sign in with SSO on the Wave Connect login page and enters your organization’s username. This username is found in your organization settings. Wave Connect redirects them to your identity provider, they authenticate, and their account is created automatically on first login. Existing account with SSO enforced: The user enters their email as usual. Wave Connect detects that SSO is enforced for their organization and redirects them to your identity provider to authenticate.
We recommend provisioning users in advance with SCIM so accounts are ready before your team logs in for the first time.

Setup

SAML SSO is configured by the Wave Connect team. To set it up:
1

Get Wave Connect's SAML details

Contact your Wave Connect account manager or support@wavecnct.com. They will provide:
  • ACS URL (Assertion Consumer Service URL)
  • Entity ID
  • Name ID Format: Email address
2

Create a Wave Connect app in your IdP

In your identity provider, create a new SAML 2.0 application for Wave Connect. Use the ACS URL and Entity ID from the previous step.
3

Share your IdP metadata with Wave Connect

Copy your identity provider’s SAML metadata URL (or download the XML file) and send it to your Wave Connect account manager.
4

Test and enable

Wave Connect configures the connection. Test with a user before enabling SSO for your full organization.

Enforcing SSO

Once SSO is enabled, you can enforce it so all users must log in through your identity provider. This disables password-based login for your organization. Contact your Wave Connect account manager to enforce SSO after testing is complete.