⚠️ Must have the "View SSO" & "Configure SSO" permissions.
Before You Begin
SSO (Single Sign-On) allows you to delegate user authentication to your identity provider. To configure SSO, you will need to exchange information between Workelo and your identity provider. Understanding SSO connection 🛜
👉 Workelo uses the SAML 2.0 protocol.
👉 For the connection to work, the employee's technical ID in Workelo must be present as the
NameIDin the SAML Response. The matching ID must be unique to each user and is case-sensitive. (See section: How to enable my users for SSO?)Once the configuration has been saved, you will not be able to change it by yourself.
Step 1 – Retrieve Workelo Metadata
From your Workelo workspace, navigate to the dedicated SSO section:
Security & Advanced tab > Security
Clicking the "Configure" button will guide you through the setup steps.
The first step is to retrieve Workelo's metadata to enter into your identity provider (IdP). This information allows your IdP to recognize Workelo as an authorized application.
Copy the Workelo metadata, then add it to your identity provider.
Step 2 – Retrieve Your Identity Provider's Metadata
Once Workelo is configured in your IdP, your identity provider will supply you with SAML metadata.
This metadata contains the necessary information to finalize the setup on Workelo's side, including:
The certificate
The Entity ID
The URL (location)
Depending on your identity provider, this information may be available in several formats (XML file or URL).
Step 3 – Add Your Metadata into Workelo
In Workelo, you can enter your identity provider's metadata in multiple ways:
Option 1 – Add a Metadata URL
If your identity provider provides a metadata URL, paste this URL into Workelo. Workelo will automatically retrieve the required setup information.
Option 2 – Import a Metadata File
If your identity provider provides a metadata file in XML format, import this file into Workelo. Workelo will automatically extract the relevant details.
Step 4 – Verify the Configuration
Before confirming the SSO configuration, verify that all entered information is correct.
⚠️ Warning: You will not be able to modify this information once saved.
Pay special attention to:
The URL
The Entity ID
The certificate and its expiration date
Step 5 – Activate SSO
Once the configuration has been verified, you can activate SSO. From this moment on, the affected users will be able to log in to Workelo via your identity provider.
How to Enable My Users for SSO?
⚠️ To access SSO login, the user's role must be authorized and the technical ID on their employee profile must be completed.
👉 By default, Admin and HR roles are enabled. All employees with these roles will have access to the SSO login button. If you wish to modify this list to add new roles, you can submit a request to Workelo.
👉 Additionally, for it to work, the technical IDs of your authorized employees must be filled in to match the format of your identity provider.
The technical ID (also known as NameID) links the user in your identity provider to the user in Workelo. This ID must be present as the NameID in the SAML Response.
You can find this ID on the employee's profile ("Account" tab, "Employees" page). It must be entered exactly as expected by your identity provider (this field is case-sensitive).
To set up these IDs in bulk for your users, you can use the bulk employee import feature by filling in the "Technical ID" column 👉 Create and modify employees 👥
Monitoring Certificate Expiration
The SAML certificate provided by your identity provider has an expiration date. When the certificate nears its expiration date, it must be renewed to avoid any login disruptions.
In Workelo, you can view the certificate's expiration date to proactively coordinate its update with your IT team and the Workelo team.
FAQ
What is SSO?
SSO allows your employees to log in to Workelo using their corporate credentials, without needing a separate Workelo password.
Which SSO protocol is used by Workelo?
Workelo uses the SAML 2.0 protocol.
Who can configure SSO?
SSO setup is typically performed by a Workelo Administrator, with the assistance of the IT team or the person managing the company's identity provider.
Where can I find my Identity Provider's metadata?
It is available within your identity management tool, under the Workelo application you created or configured. Depending on the tool used, it may be provided as a URL, a file, or fields to copy manually.
Why is the certificate important and how to update it?
The certificate secures the exchange of information between your identity provider and Workelo. If it expires, SSO login may stop working. It is therefore important to renew it before its expiration date.
You can provide the new metadata to Workelo, which will then modify the certificate without any interruption.
What should I do if the connection isn't working?
First, check that:
The metadata is in SAML 2.0 format
The certificate is valid
The Entity ID is correct
The login URL is correct
The
NameIDmatches the expected identifier in Workelo (NameID= Technical ID of the user trying to log in via SSO)
If the issue persists, contact your Workelo representative with the configuration details and any error messages received. More information can also be found here: Understanding SSO connection 🛜
The SSO is different across my organizations. What should I do?
Please contact Workelo for further instructions. By default, only the ‘primary’ SSO will be shown in this area.
Summary
To configure SSO in Workelo:
Retrieve Workelo metadata
Add Workelo to your identity provider
Retrieve your identity provider's metadata
Add it to Workelo
Verify the configuration
Verify role permissions
Ensure technical IDs for your employees are filled in with the correct expected
NameIDformatActivate SSO
Once configured, SSO simplifies access to Workelo and allows your employees to use their standard corporate credentials.