- 17 Dec 2025
- 4 Minutes To Read
- Print
- DarkLight
- PDF
Set up Single Sign On
- Updated On 17 Dec 2025
- 4 Minutes To Read
- Print
- DarkLight
- PDF
Whatfix supports login with Single Sign-on (SSO) for content creators who use the Whatfix dashboard. SSO is an authentication process that enables users to access multiple applications with one set of login credentials. The use of SSO significantly improves user experience by reducing password fatigue (not having to remember multiple passwords) and enhances security by decreasing the potential attack surface.
Note:
An Identity Provider (IdP) is an authority system that holds and verifies the user authentication information. Whatfix interacts with your IdP and trusts the information provided by the IdP to gain access to the application. Whatfix supports the following identity providers: Okta, Azure Active Directory, or any identity provider compliant with SAML 2.0 that works with Whatfix SSO.
How does SSO work in Whatfix?
SSO-enabled enterprises have the following login screen:
When you click Sign in with SSO, you are redirected to the configured IdP.

Once you enter the credentials of IdP, you are verified and redirected to your Whatfix account.
Info:
Expand the following accordions for more details.
Set up SSO configuration using the Whatfix dashboard
Only an Account Manager can perform the following task. For more information about available roles, see Whatfix User Roles.
Step 1: Access SSO Configuration
On the Whatfix Guidance dashboard, click Settings.

Under Setup, click SSO and authentication.

On the Set up SSO section, click Start.

Note:
Here’s what you can do once SSO is enabled on the Whatfix Guidance dashboard:
Dashboard authentication: Enhance Whatfix dashboard security by controlling who has access.
End-user authentication: Ensure secure and accurate end-user identification.
Additional user attribute addition: Capture end-user attributes to perform role-based segmentation.
The Whatfix Single Sign-on page displays the following stages:
Whatfix information
Identity provider information
Test and enable
Step 2: Add Whatfix information
Under the Whatfix information step, copy the following details from the dashboard using the copy icon and paste them into your Identity provider:

The following table describes the Whatfix information on the dashboard:
Whatfix Information | Description |
|---|---|
Entity ID | The unique identifier used by the Identity Provider (IdP) to recognize and validate the Whatfix application (Service Provider). |
Assertion Consumer Service (ACS) URL | The Whatfix endpoint that receives and processes the SAML Assertion (user authentication data) from the IdP. |
Relay State | The default Whatfix dashboard URL for the Enterprise Tenant (ENT) where users are redirected after successful SSO login. |
Sign-in URL | The Whatfix dashboard URL where Whatfix redirects the user to begin the SSO authentication process. |
b. Click Continue.

Step 3: Add Identity provider information
Choose how you want to share your identity provider configuration with Whatfix, using any of the following methods:

Option 1 - Upload XML file: Upload your SAML metadata XML file to extract details automatically. The XML file can be fetched from your IdP.

Option 2 – Enter manually: Manually enter the following fields:

The following table describes the information that you need to enter manually:
Manual Data
Description
Identity provider
Your identity provider is the service that manages logins and passwords for your users.
Issuer
Issuer is similar to the unique “digital ID card” for your company’s login system (where you prove who you are).
Single Sign-on URL
The Single Sign-on URL is the web address where the Identity Provider handles requests to verify who you are for single sign-on.
X509 Certificate
An X509 certificate is a digital ID that proves a website or person is genuine and helps secure online communication.
SAML Identity Location
SAML identity location tells the system where to find your unique user ID within the digital login message.
b. Click Continue.

Step 4: Perform Test and enable
Under Test your single sign-on setup, click Run test to simulate and verify your SSO connection.

You are redirected to your identity provider’s sign-in page (for example, Okta). Once the test is completed, you can see the message Test successful. 
Enable the Dashboard authentication toggle to activate the SSO login for admins and content authors.

In the dialog box, click Confirm.

Once the authentication is done, click Save.

Info:
You cannot configure both US and EU Whatfix accounts simultaneously via the same SSO configuration since the ACS URL domain is different for both US and EU accounts.
SSO users cannot view the Change Password option in the admin menu. You must perform any changes at the Identity Provider level.
Currently, Whatfix does not support SLO (Single Log Out). When a user signs out of a Whatfix account, it does not log them out of the IdP.
If a user has access to more than one enterprise (ENT) and logs into any one of them using SSO, they are automatically logged into all the other ENTs that have the same SSO configurations. Thus, they can switch between enterprises from their Whatfix Dashboard.
Once you complete dashboard authentication, you can set up the end-user authentication process. For more information, see how to set up end-user authentication.
Follow the requirements to enable SSO on your account
The following information is exchanged with Whatfix to enable SSO for your account:
Information | Detail | Example |
|---|---|---|
The organization provides this information | Enterprise Name* | XYZ corp |
IdP EntityId* |
| |
IdP SSO Service URL* |
| |
X509 certificate* | ||
SAML identity location* | <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</NameIDFormat> OR <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic" Name="User.email"> | |
Whatfix provides this information | Identifier/Audience URI/Entity ID | whatfix |
ACS URL* |
| |
ACS URL* (EU Dashboard) |
|
* The value of each detail varies for every organization. For more details, contact support@whatfix.com.
Enable End-user authentication on Dashboard
If you have deployed Whatfix content on your application, the End-user authentication feature prompts your end users to authenticate themselves with valid credentials using your organization’s Single Sign-on (SSO). For more information, see Set up End-User Authentication.


