Integration documentation

Enterprise Identity Integrations

A public architecture overview—not a claim that every internal endpoint is a supported public developer API.

Enterprise SSO documentation

CardIQ has a SAML metadata configuration foundation, while automatic redirect, enforced login and native SCIM are not currently active.

Supported integration paths today

Availability depends on plan, API scope and configuration.

Admin and bulk provisioning

Company Admin entry is supported. Bulk CSV employee upload is available on entitled plans.

API

Company-scoped API-key workflows and selected employee/company integration surfaces exist. Exact scopes and production access must be confirmed during integration setup; this is an overview, not a complete API reference.

Webhooks and CRM

Signed outbound lead_created webhook delivery to an HTTPS receiver is supported where configured. CRM-oriented integrations exist; lifecycle-event webhook coverage is not claimed.

Security expectations

Use authorized admins, least-privilege scopes, protected and revocable API keys, HTTPS receivers, signature validation, tenant boundaries and audit review. No public rate limit is promised here.

Named integration status

Availability below distinguishes read-only identity preview from provisioning connectors.

Microsoft Entra ID — OIDC and Phase 2A preview

Phase 2B adds controlled synchronization: administrators can use mapped-user OIDC login and selected-group preview, then explicitly approve employee linking, non-login provisioning, selected profile-field updates, or non-destructive deactivation. Nothing applies automatically. Scheduled sync, group-to-role automation, unrestricted JIT provisioning, native SCIM and direct LDAP/LDAPS are not supported.

Okta — Not currently supported

No native Okta connector is represented as available.

SCIM — Not currently supported

CardIQ does not currently provide native SCIM provisioning or deprovisioning.

SAML SSO — Available where configured/supported

Enterprise SSO foundations exist, but provider/protocol support and entitlement must be confirmed for the deployment; this is not SCIM.

Google Workspace — Not currently supported natively

No native directory-provisioning connector is documented. Generic import or an approved custom API workflow may be evaluated.

Workday — Not currently supported natively

No native Workday connector is documented. Generic import or an approved custom API workflow may be evaluated.

Provisioning and deprovisioning model

Use only the path confirmed for the deployment.

Current workflow

Admins create/update/deactivate employees; entitled teams can bulk import. Supported API workflows may automate selected fields or statuses.

Integration-ready pattern

HR / Directory / Admin Source → approved API or import layer → CardIQ company identity → employee identity → supported public surfaces.

Offboarding path

Employee disabled/deactivated → CardIQ identity inactive → public verification no longer presents active company identity.

No implied directory automation

Do not design around SCIM, Entra, Okta, Google Workspace or Workday automation until CardIQ explicitly confirms a supported connector or custom scope.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing