Verify your domain for SSO
Last updated: September 5, 2026
Available on: Mac, Windows, iOS, Android. Domain registration and SSO configuration happen in a web browser.
If your organization uses a .edu, .gov, .mil, or university domain, self-service registration is blocked until support adds your domain to your enterprise account. Get it registered and finish SSO setup — usually within one business day.
Important: SSO requires an enterprise account, and enforcing SSO for all users requires an active enterprise subscription.
How to get your domain registered
Standard commercial domains (e.g., yourcompany.com) register automatically when an enterprise account is created. If your domain is restricted, register it manually:
Contact Wispr Flow support with your organization name, email domain (e.g., yourschool.edu), and identity provider if known.
Wait for confirmation that your domain is registered — typically within one business day.
Open the identity provider admin portal link in your Wispr Flow admin settings and configure your IdP.
Activate SSO by completing the connection step in your Wispr Flow admin settings. "SSO connected successfully" confirms it worked. Otherwise:
"SSO not connected" — no matching connection was found in your admin portal yet.
"SSO connection is not active" — the connection exists but hasn't been activated.
"Failed to connect SSO" — verify your IdP settings and retry the connect step.
Enable the Enforce SSO toggle (optional) once you see "SSO connected successfully."
Tip: Your configuration is saved as you go, so if support registers your domain after you've configured your IdP, you can pick up where you left off.
FAQs
My domain isn't .gov, .edu, or .mil, but I still can't register it. Why?
University domains and domains flagged for sales assistance are also restricted. Contact support and they'll register it for you.
Can I register multiple domains for my organization?
Yes. Send support the full list of domains and they'll register them all for your enterprise.
Does domain registration cover subdomains?
No. Domains are matched exactly at sign-in, so each subdomain (e.g., @yourcompany.com and @mail.yourcompany.com) must be registered separately. Contact support to add them.
Is domain matching case-sensitive?
No. Email domains are normalized to lowercase during signup and SSO sign-in.
What if our organization uses SCIM directory sync?
Self-service sign-up is blocked for your domain. Accounts are created through your identity provider's directory sync, and provisioned users receive a welcome email; if provisioning fails, they may get an email invitation instead.
Roles: SCIM-provisioned users get the "Member" role; SCIM never provisions admins.
Membership changes: adding or removing users in the admin portal is blocked — all changes go through your IdP's directory sync.
Skipped users: SCIM neither provisions nor invites users at the seat limit, users whose email domain isn't registered, or users whose account already belongs to a different enterprise — contact support for the last case.
Removals and directory changes: removals that would leave your enterprise with no admin or no billable user are blocked. If your IdP directory is re-linked or rotated, events from the old directory are dropped — re-run a sync after changing IdPs.
Does SSO work from my identity provider's dashboard?
Yes. SSO works from the Wispr Flow sign-in screen or from a tile in your IdP dashboard (such as Okta).
What's the difference between "SSO not configured" and "SSO not with organization" errors?
They point to different causes:
SSO not with organization: the user's email domain isn't linked to any enterprise. Contact support to register it.
SSO not configured: the enterprise exists but its SSO configuration is incomplete. The admin finishes setup in the admin portal.
What SSO sign-in errors might users see on mobile?
On iOS, an "Error" alert appears if the sign-in page returns an incomplete result or fails to open; cancelling shows nothing. On Android, red text reads "Couldn't open the sign-in page. Please try again." or "Sign-in didn't finish. Please try again."; typing in the email field clears the error. If the app is closed mid-SSO on Android, a "Finish signing in" screen appears and you'll need to re-enter your email.
Limitations and notes
Domains blocked from self-registration (require support or sales):
.edu, .gov, .mil, .int: educational, government, military, and international treaty organizations, including country variants (e.g., .gov.uk, .edu.au). These return "Forbidden domain."
University and academic domains outside the .edu TLD are also treated as forbidden.
Sales-assisted domains: flagged for sales follow-up rather than hard-blocked, and return "This domain requires sales assistance."
Some domains in these categories are pre-approved and can self-register. If you think yours should be allowed, contact support.
Sign-in differences by platform:
iOS: SSO is hidden by default — tap "More options" (reveal order: Microsoft, SSO, then Email) and choose "Continue with SSO."
Android: all sign-in options, including SSO, are visible by default.
Both mobile platforms: the SSO screen asks for your work email address, not a company name or domain, and Continue stays disabled until the address is a valid email.
Mac and Windows: sign-in goes through your browser via a single "Sign in via browser" button — there's no in-app SSO selector.
Warning: Enterprises may separately restrict access to approved networks. Contact support for details.
IP allowlist details for admins:
The setting lives in the enterprise web console under Settings, as an "IP allowlist" card showing the entry count (e.g. "IP allowlist (3 CIDRs)") or "IP allowlist (locked by Wispr)" with controls disabled when Wispr has locked it.
There is no limit on CIDR entries. Paste them one per line or comma-separated; they are normalized to their network address and duplicates are collapsed (for example, 192.168.1.5/24 becomes 192.168.1.0/24).
Wildcard entries (e.g., 0.0.0.0/0) are rejected. To disable enforcement, remove the entry.
Save is blocked with a self-lockout warning if the admin's own current IP isn't covered by the proposed ranges. Admins can check their egress IP from the admin portal even when blocked by the allowlist.
Disabling the allowlist prompts "Disable IP allowlist?" and clears all saved ranges.
Adding or changing registered domains after setup requires contacting support — there is no self-serve domain management interface.
Still need help?
Reach out to our support team if:
You're unsure whether your domain requires manual registration, or it's been more than one business day since you requested it.
You need to change or add domains to an existing SSO configuration.
You see an SSO connection error in the admin portal, or your users see an "SSO not configured" page.
Include your organization name, email domain, identity provider, and any error messages. Most SSO setup issues are resolved in one reply.