Note: SSO/SAML is only available for customers on our Enterprise plan.
Currently, only service-provider initiated SAML 2.0 flows are supported.
Security Assertion Markup Language (SAML) is a security standard for logging into applications. SAML-based single sign-on (SSO) gives users access to Waitwhile through an identity provider (IDP) of your choice.
Steps for enabling SSO/SAML on your Waitwhile account
NOTE: SSO/SAML are only available for customers on the Enterprise Plan.
1. Configure your Identity Provider
As a first step, you’ll need to add Waitwhile app to your identity provider.
Use the following information to complete the configuration process with your IdP:
SP Entity ID: waitwhile
SP Assertion Consumer Service URL (ACS URL): https://auth.waitwhile.com/__/auth/handler
SP Start URL (optional): https://app.waitwhile.com/login/sso
2. Setup SAML/SSO for Waitwhile
Once you’ve configured your identity provider (IdP), complete the Waitwhile SAML/SSO Setup Form by providing the following information:
IdP Entity ID: This is the identifier for the Identity Provider you are using
IdP SSO URL: This is the URL used to start the login process
Public Certificate: This allows to validate SAML requests from your identity provider. It must be an X.509 certificate in the base64 format.
This value begins with '-----BEGIN CERTIFICATE-----'.
List of Allowed Domains (ie. @yourbusiness.com): Will be used to verify if users logging into your account have the appropriate email domains.
With SAML/SSO enabled you will only be able to invite users using email addresses that match your allowed domain(s).
3. We will review and configure SAML/SSO for you
Typically 2-3 business days after submitting the SAML/SSO setup form you should receive an email from a member of the Waitwhile team letting you know that SAML/SSO has successfully been enabled for your account and added users (with allowed email domains) can begin using app.waitwhile.com/login/sso to login using SSO/SAML.
4. View your configuration in Waitwhile
Once configured, you will be able to view your SSO set up in Account Settings > Single Sign-on which will detail out your list of allowed domains and whether JIT is enabled or disabled on the account.
Note: The data that appears under Single sign-on is read only. You will need to contact your Waitwhile Customer Success Manager for any change requests.
Have additional questions or need assistance? Reach out to us via chat or at support@waitwhile.com.