Top
Set up Single Sign On
  • 17 Dec 2025
  • 4 Minutes To Read
  • Dark
    Light
  • PDF

Set up Single Sign On

  • Dark
    Light
  • PDF

Article summary

Whatfix supports login with Single Sign-on (SSO) for content creators who use the Whatfix dashboard. SSO is an authentication process that enables users to access multiple applications with one set of login credentials. The use of SSO significantly improves user experience by reducing password fatigue (not having to remember multiple passwords) and enhances security by decreasing the potential attack surface.

Note:

An Identity Provider (IdP) is an authority system that holds and verifies the user authentication information. Whatfix interacts with your IdP and trusts the information provided by the IdP to gain access to the application. Whatfix supports the following identity providers: Okta, Azure Active Directory, or any identity provider compliant with SAML 2.0 that works with Whatfix SSO.

How does SSO work in Whatfix?

SSO-enabled enterprises have the following login screen:

  • When you click Sign in with SSO, you are redirected to the configured IdP.

    SSO login using Dashboard

  • Once you enter the credentials of IdP, you are verified and redirected to your Whatfix account.

Info:

Expand the following accordions for more details.

Set up SSO configuration using the Whatfix dashboard

Note:

Only an Account Manager can perform the following task. For more information about available roles, see Whatfix User Roles.

Step 1: Access SSO Configuration

  1. On the Whatfix Guidance dashboard, click Settings.

    Click Settings on the dashboard

  2. Under Setup, click SSO and authentication.

    Click SSO and authentication on dashboard under settings

  3. On the Set up SSO section, click Start. Click Start under Set up SSO on dashboard

Note:

Here’s what you can do once SSO is enabled on the Whatfix Guidance dashboard:

  • Dashboard authentication: Enhance Whatfix dashboard security by controlling who has access.

  • End-user authentication: Ensure secure and accurate end-user identification.

  • Additional user attribute addition: Capture end-user attributes to perform role-based segmentation. Here is what you can do with SSO


The Whatfix Single Sign-on page displays the following stages:

  • Whatfix information

  • Identity provider information

  • Test and enable

Step 2: Add Whatfix information

  1. Under the Whatfix information step, copy the following details from the dashboard using the copy icon and paste them into your Identity provider: Copy all the Whatfix information to your idp site

The following table describes the Whatfix information on the dashboard:

Whatfix Information

Description

Entity ID

The unique identifier used by the Identity Provider (IdP) to recognize and validate the Whatfix application (Service Provider).

Assertion Consumer Service (ACS) URL

The Whatfix endpoint that receives and processes the SAML Assertion (user authentication data) from the IdP.

Relay State

The default Whatfix dashboard URL for the Enterprise Tenant (ENT) where users are redirected after successful SSO login.

Sign-in URL

The Whatfix dashboard URL where Whatfix redirects the user to begin the SSO authentication process.

b. Click Continue.

Click continue to proceed with SSO on dashboard


Step 3: Add Identity provider information

  1. Choose how you want to share your identity provider configuration with Whatfix, using any of the following methods:

    Add IDP information for SSO

  • Option 1 - Upload XML file: Upload your SAML metadata XML file to extract details automatically. The XML file can be fetched from your IdP.

    Upload XML metadata for SSO

  • Option 2 – Enter manually: Manually enter the following fields:

    Enter the data manually for SSO

    The following table describes the information that you need to enter manually:

    Manual Data

    Description

    Identity provider

    Your identity provider is the service that manages logins and passwords for your users.

    Issuer

    Issuer is similar to the unique “digital ID card” for your company’s login system (where you prove who you are).

    Single Sign-on URL

    The Single Sign-on URL is the web address where the Identity Provider handles requests to verify who you are for single sign-on.

    X509 Certificate

    An X509 certificate is a digital ID that proves a website or person is genuine and helps secure online communication.

    SAML Identity Location

    SAML identity location tells the system where to find your unique user ID within the digital login message.

    b. Click Continue.  Click continue to proceed with SSO on dashboard


Step 4: Perform Test and enable

  1. Under Test your single sign-on setup, click Run test to simulate and verify your SSO connection.

    Click Run test for SSO

You are redirected to your identity provider’s sign-in page (for example, Okta). Once the test is completed, you can see the message Test successful.  Success message for test SSO on dashboard

  1. Enable the Dashboard authentication toggle to activate the SSO login for admins and content authors.Enable the dashboard authentication toggle

  2. In the dialog box, click Confirm.

    Click confirm for dashboard authentication

  3. Once the authentication is done, click Save. Click Save after dashboard authentication is done

Info:

  • You cannot configure both US and EU Whatfix accounts simultaneously via the same SSO configuration since the ACS URL domain is different for both US and EU accounts.

  • SSO users cannot view the Change Password option in the admin menu. You must perform any changes at the Identity Provider level.

  • Currently, Whatfix does not support SLO (Single Log Out). When a user signs out of a Whatfix account, it does not log them out of the IdP.

  • If a user has access to more than one enterprise (ENT) and logs into any one of them using SSO, they are automatically logged into all the other ENTs that have the same SSO configurations. Thus, they can switch between enterprises from their Whatfix Dashboard.

  • Once you complete dashboard authentication, you can set up the end-user authentication process. For more information, see how to set up end-user authentication.

    Set up end-user authentication on dashboard for users

Follow the requirements to enable SSO on your account

The following information is exchanged with Whatfix to enable SSO for your account:

Information

Detail

Example

The organization provides this information

Enterprise Name*

XYZ corp

IdP EntityId*

https://app.onelogin.com/saml/metadata/905b5aec-defd-4f7a-a910-dae67c220cbe

IdP SSO Service URL*

https://ddash.onelogin.com/trust/saml2/http-post/sso/884595

X509 certificate*

SAML identity location*
(If the NameID is not available, you can provide the attribute element instead)

<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</NameIDFormat>

OR

<saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic" Name="User.email">

Whatfix provides this information

Identifier/Audience URI/Entity ID

whatfix

ACS URL*

https://whatfix.com/saml_auth/?service=samlFromIdp

ACS URL* (EU Dashboard)

https://eu.whatfix.com/saml_auth/?service=samlFromIdp

* The value of each detail varies for every organization. For more details, contact support@whatfix.com.

Enable End-user authentication on Dashboard

If you have deployed Whatfix content on your application, the End-user authentication feature prompts your end users to authenticate themselves with valid credentials using your organization’s Single Sign-on (SSO). For more information, see Set up End-User Authentication.


Was this article helpful?


Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.