Available on the Enterprise plan.
Overview
SAML SSO lets your team log in to Wave Connect through your organization’s identity provider (IdP). Instead of managing a separate Wave Connect password, users authenticate with the same credentials they use for everything else. Wave Connect supports SAML 2.0 and works with any standards-compliant identity provider, including Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, and Ping Identity. Wave Connect also supports OpenID Connect (OIDC). Contact support@wavecnct.com if you need a guide.How It Works
There are two login paths depending on whether the user already has a Wave Connect account. No account yet: The user clicks Sign in with SSO on the Wave Connect login page and enters your organization’s username. This username is found in your organization settings. Wave Connect redirects them to your identity provider, they authenticate, and their account is created automatically on first login. Existing account with SSO enforced: The user enters their email as usual. Wave Connect detects that SSO is enforced for their organization and redirects them to your identity provider to authenticate.Setup
SAML SSO is configured by the Wave Connect team. To set it up:1
Get Wave Connect's SAML details
Contact your Wave Connect account manager or support@wavecnct.com. They will provide:
- ACS URL (Assertion Consumer Service URL)
- Entity ID
- Name ID Format: Email address
2
Create a Wave Connect app in your IdP
In your identity provider, create a new SAML 2.0 application for Wave Connect. Use the ACS URL and Entity ID from the previous step.
3
Share your IdP metadata with Wave Connect
Copy your identity provider’s SAML metadata URL (or download the XML file) and send it to your Wave Connect account manager.
4
Test and enable
Wave Connect configures the connection. Test with a user before enabling SSO for your full organization.