Enterprise identity documentation

CardIQ Enterprise SSO

SAML configuration foundation for enterprise identity integration

Current capability status

Availability is entitlement- and configuration-dependent. This is a configuration foundation, not a completed login integration.

Available now: SAML configuration foundation

CardIQ stores provider type, Entity ID, SSO URL, certificate fingerprint or uploaded certificate reference, and company-level activation/enforcement preferences.

Not active yet: login enforcement

Automatic SSO redirect and enforced SSO login are not active. Marking configuration as enabled or enforced only prepares metadata and a future policy preference.

Existing login remains active

Email/password login remains unchanged until SSO activation and login enforcement are implemented.

Not active yet: automated provisioning

Native directory provisioning, SCIM provisioning and SCIM deprovisioning are not currently available.

Architecture

Enterprise Identity ProviderSAML Metadata ConfigurationCardIQ Enterprise SSO FoundationFuture Login Enforcement
Current implementation stores and validates configuration metadata but does not yet replace the existing CardIQ login flow.

Identity-provider status

Provider names below explain the metadata model; they are not tested-compatibility claims.

Microsoft Entra ID

CardIQ provides company-bound Entra OIDC sign-in for pre-mapped users and, where configured, a read-only selected-group directory preview. It does not automatically provision, update, or deactivate employees and does not enforce SSO.

Okta

Okta can conceptually act as a SAML identity provider. CardIQ does not currently claim a native Okta integration or tested compatibility.

Other SAML providers

The configuration model is provider-agnostic at the supported metadata level. This does not claim certification or tested compatibility with any specific provider.

Does CardIQ support SCIM?

Native SCIM provisioning and deprovisioning are not currently available.

SSO is authentication

Single sign-on controls authentication and login. SAML SSO does not automatically mean SCIM provisioning.

Provisioning manages accounts

Provisioning creates, updates or deactivates user accounts and identities. CardIQ’s current SSO foundation concerns authentication configuration, not automated provisioning.

API paths are separate

Authorized admin entry and entitled bulk import are available. A custom, company-scoped API path may be evaluated only where CardIQ confirms coverage; an API integration must not be described as SCIM support.

Admin configuration guidance

The Enterprise admin configuration page prepares metadata; these controls do not currently activate full SSO enforcement.

Provider Type, Entity ID and SSO URL

Select SAML, then enter the safe Entity ID and HTTPS SSO URL supplied for the identity provider.

Certificate metadata

Enter a SHA-256 Certificate Fingerprint or an Uploaded Certificate Reference according to the current implementation; do not paste certificate content.

Activation and future enforcement

Use “Enable after metadata is complete,” then “Mark as enforced for future login policy.” These values store readiness and policy intent only; no automatic redirect occurs.

Security boundaries

Keep secrets out of metadata

Do not paste private keys, secrets, tokens, raw certificates or raw SAML payloads. Follow the current fingerprint/reference validation rules.

Metadata is not enforcement

Saving, enabling or marking metadata as enforced does not automatically replace password login or redirect a user to an identity provider.

Authorization remains server-controlled

Super Admin and Company Admin permissions remain server-controlled. SSO does not replace company lifecycle or employee lifecycle controls.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing