SAML SSO is available to platforms on a dedicated Cadana identity pool, which every platform created since the pool-per-platform rollout has. Contact your account manager if you are unsure.
How It Works
- User opens your white-label app and chooses Sign in with SSO
- Cadana sends them to your identity provider
- They authenticate there, including any MFA your provider enforces
- Your provider returns a SAML assertion with the user’s email
- Cadana matches the email to an existing Cadana user on your platform and starts their session
Before You Start
Ask your account manager for the two values below. They are fixed for your platform and available before anything is set up on either side, so this is the first thing to do.Step 1: Create the Cadana Application in Your Identity Provider
Create a new SAML 2.0 application in your identity provider and give it the two values you received:
Then make sure the assertion carries the user’s email address as an attribute. Cadana matches users by email, so this attribute must contain the same address the user has on their Cadana account.
- Okta
- Microsoft Entra ID
- Google Workspace
Applications → Create App Integration → SAML 2.0. Set the Single sign-on URL to the ACS URL and the Audience URI to the Entity ID. Under Attribute Statements add
email → user.email.Step 2: Send Cadana Your Provider Details
Send your account manager:
If your provider does not publish a metadata URL that Cadana can fetch, send the metadata XML file instead.
SAML settings are configured by your Cadana account manager. Self-service configuration in the Dashboard is coming soon.
Step 3: Make Sure Each User Exists in Cadana
SAML SSO signs in users who already have a Cadana account on your platform. It never creates accounts. Create your users as you do today, through the Dashboard or withPOST /v1/users/invite. If users will only ever sign in through SSO, set suppressWelcomeEmail to true so they are not asked to set a Cadana password.
The email on the Cadana user must match the email your identity provider asserts, character for character apart from letter case.
Linking is automatic. The first time a user signs in through SSO, Cadana matches the asserted email to their account and links the two. Users who existed before SSO was enabled and users created afterwards are treated the same way.
Step 4: Sign In
Users open your white-label app and choose Sign in with SSO. To take a user who is already signed in to your own app straight into Cadana, link to the white-label login page withsso=1. The app starts the SSO flow at once; because the user already has a session with your identity provider there is no prompt, and they land signed in. Add redirect to choose the page:
redirect must be a path inside the app. External URLs are ignored. Without sso=1 the login page is shown with the SSO button.
Logins always start from the white-label app. If you want a tile for Cadana in your identity provider’s app launcher, point it at your white-label login page (for example https://payroll.yourcompany.com/login): the user clicks the SSO button there and, because they are already signed in with you, lands in Cadana without seeing another prompt. An assertion sent to Cadana without that first step is rejected.
What to Expect
Troubleshooting
Next Steps
Custom Authentication
Sign users in from your own product with a JWT exchange
Custom Domain
Serve the white-label app from your own domain
Onboard Workers
Create Person and User records
White-Label UI Overview
Customize the white-label app for your brand