Skip to main content

Single sign-on (SSO)

Settings → Organization → Security → Single sign-on. Visible to admins who can manage security.
WonkaChat supports OpenID Connect (OIDC) with Microsoft, Google or a custom provider, and SAML. Only one protocol is used for login at a time. Before you start, get from your identity provider (IT admin):
  • OIDC: Tenant ID (Microsoft) or Client ID, plus a client secret, and — for a custom provider — the Issuer URL.
  • SAML: the IdP metadata (a URL or an XML file), or manually the IdP SSO URL, IdP entity ID and the IdP certificate.

Set up OIDC

1

Pick a provider

Under Authentication, choose Microsoft, Google or Custom.
2

Enter provider details

  • Microsoft: Tenant ID, Client ID.
  • Google: Client ID.
  • Custom: Issuer URL, Client ID.
Enter the primary client secret (and optionally a secondary client secret with its own expiry, for rotation).
3

Register the redirect URI

Copy the Redirect URI shown and add it in your identity provider’s app registration.
4

Test, then turn on

Use Test to confirm the secret is accepted, then switch the provider on. Use Use [provider] for login to make it the active protocol.

Set up SAML

1

Import metadata

Paste a Metadata URL or upload a Metadata file, then Parse metadata to fill the fields automatically — or enter them by hand: IdP SSO URL, IdP entity ID, and the IdP certificate.
2

Register the ACS URL

Copy the Assertion Consumer Service (ACS) URL and register it as the Reply URL in your identity provider. The SP entity ID defaults to the ACS URL — override it only if your IdP requires a different identifier.
3

Optional claims and signing

Set the Email claim and Name claim if your IdP uses non-standard attribute names, choose the NameID format (Email address, Persistent, Transient or Unspecified), and require signed assertions and/or a signed authentication response if your IdP supports it.
4

Test, then turn on

Test the configuration, then switch SAML on and set it as the login method.

Require SSO for non-admin users

Once a protocol is live, turn on Require SSO for non-admin users under Login policy. Only organization admins can still sign in with email and password; everyone else must use SSO.
Clearing a provider’s configuration deletes its saved secrets and certificates. Turning a protocol off only pauses login — secrets are kept. Rotate secrets by adding a new one as secondary before removing the primary, to avoid a login gap.

Two-factor authentication (2FA)

Every user can enable 2FA for their own account from Settings → Account → Two-Factor Authentication (2FA).
1

Start setup

Click Setup 2FA.
2

Scan the QR code

Scan it with your authenticator app (any TOTP app), or enter the secret manually.
3

Verify

Enter the code your app shows to confirm setup.
4

Save your backup codes

Download the backup codes shown — they’re displayed only once. Store them somewhere safe; you’ll need one if you lose access to your authenticator app.
You can Disable 2FA at any time from the same page, or use Use 2FA Code Instead at sign-in if prompted for a backup code.