Available now: SAML configuration foundation
CardIQ stores provider type, Entity ID, SSO URL, certificate fingerprint or uploaded certificate reference, and company-level activation/enforcement preferences.
Enterprise identity documentation
SAML configuration foundation for enterprise identity integration
Availability is entitlement- and configuration-dependent. This is a configuration foundation, not a completed login integration.
CardIQ stores provider type, Entity ID, SSO URL, certificate fingerprint or uploaded certificate reference, and company-level activation/enforcement preferences.
Automatic SSO redirect and enforced SSO login are not active. Marking configuration as enabled or enforced only prepares metadata and a future policy preference.
Email/password login remains unchanged until SSO activation and login enforcement are implemented.
Native directory provisioning, SCIM provisioning and SCIM deprovisioning are not currently available.
Provider names below explain the metadata model; they are not tested-compatibility claims.
CardIQ provides company-bound Entra OIDC sign-in for pre-mapped users and, where configured, a read-only selected-group directory preview. It does not automatically provision, update, or deactivate employees and does not enforce SSO.
Okta can conceptually act as a SAML identity provider. CardIQ does not currently claim a native Okta integration or tested compatibility.
The configuration model is provider-agnostic at the supported metadata level. This does not claim certification or tested compatibility with any specific provider.
Native SCIM provisioning and deprovisioning are not currently available.
Single sign-on controls authentication and login. SAML SSO does not automatically mean SCIM provisioning.
Provisioning creates, updates or deactivates user accounts and identities. CardIQ’s current SSO foundation concerns authentication configuration, not automated provisioning.
Authorized admin entry and entitled bulk import are available. A custom, company-scoped API path may be evaluated only where CardIQ confirms coverage; an API integration must not be described as SCIM support.
The Enterprise admin configuration page prepares metadata; these controls do not currently activate full SSO enforcement.
Select SAML, then enter the safe Entity ID and HTTPS SSO URL supplied for the identity provider.
Enter a SHA-256 Certificate Fingerprint or an Uploaded Certificate Reference according to the current implementation; do not paste certificate content.
Use “Enable after metadata is complete,” then “Mark as enforced for future login policy.” These values store readiness and policy intent only; no automatic redirect occurs.
Do not paste private keys, secrets, tokens, raw certificates or raw SAML payloads. Follow the current fingerprint/reference validation rules.
Saving, enabling or marking metadata as enforced does not automatically replace password login or redirect a user to an identity provider.
Super Admin and Company Admin permissions remain server-controlled. SSO does not replace company lifecycle or employee lifecycle controls.
Explore the CardIQ platform or review the workflow from verification through identity deactivation.
See how CardIQ works View pricing