Set up SAML Single Sign-On (SSO) so your team logs into Weel through your existing identity provider, for faster onboarding and offboarding and a more secure, centrally managed login.
Before you start
- Your business needs to be on Weel's Enterprise plan.
- You'll need admin access to your identity provider (e.g. Okta, Azure AD) to add Weel as an application.
- Weel supports both SAML 2.0 and OIDC-based SSO. This article covers SAML setup; if your identity provider uses OIDC instead, let your Weel contact know since the setup steps are a little different.
Steps
- Contact Weel to get started. Reach out to your account manager, or email customerservice@letsweel.com, to set up SAML SSO. We'll run the setup with you directly. If your plan doesn't already include SSO, we'll confirm add-on eligibility with you at this point too.
-
Add Weel as an application in your identity provider (Okta, Azure Active Directory/Entra ID, ADFS, Auth0, OneLogin, Ping Identity, Salesforce, or any other provider using generic SAML 2.0), using these values:
- Identifier (Entity ID):
urn:amazon:cognito:sp:ap-southeast-2_Cpf8dMfdn - Reply URL (ACS URL):
https://divipay.auth.ap-southeast-2.amazoncognito.com/saml2/idpresponse - Sign on URL: https://app.letsweel.com/app/login
- If you use Google Workspace, map the Primary email attribute to Email.
- If you use Microsoft Azure AD (Entra ID), go to Enterprise Applications > [your Weel app] > Single Sign-On > Attributes & Claims and edit the Unique User Identifier (Name ID): set Name identifier format to Persistent and the Source attribute to
user.objectIdinstead of email. This keeps login working even if a staff member's email address later changes or differs in capitalisation. - Enable the application for all relevant users in your identity provider.
- Identifier (Entity ID):
- Send us your SAML metadata: the metadata document endpoint URL, your provider type, and which SAML claim carries the user's email. Use the configuration form your Weel contact shares with you, or email the details to customerservice@letsweel.com.
- Wait for Weel to connect the integration, typically within one business day. We test the connection with your admin users first, then roll out to everyone, and can schedule the final cutover outside business hours if that suits your team.
- Test that SSO login works end to end before it goes live for your whole team.
-
Confirm SSO is live. Staff on a domain configured for SSO will log in through your identity provider instead of a Weel password.
- Sign in only from https://app.letsweel.com/app/login and bookmark it. Weel only supports logins that start from Weel (SP-initiated SSO); logins started from inside your identity provider's own app portal (IdP-initiated SSO) aren't supported, since that flow is more vulnerable to interception and replay attacks.
What happens next
You don't need to send us anything when your identity provider's SAML certificate is expiring or has expired. Weel stores only your SAML metadata URL, never a certificate file, and we don't accept certificate uploads, so it updates automatically whenever your identity provider rotates the certificate. If you're ever unsure the connection is still working, or your metadata URL changes, contact us at customerservice@letsweel.com and we'll check it.