Configure SSO
Last updated: September 20, 2026
Available on: Configured in a web browser at admin.wisprflow.ai. SSO sign-in works on Mac, Windows, iOS, and Android.
Let your team sign in to Wispr Flow with your company's identity provider. Admins configure SAML single sign-on (SSO) in the admin portal.
Before you start
Identity provider: Access to your identity provider, such as Okta, Microsoft Entra ID (Azure AD), or Google Workspace, with permission to create a SAML application.
Role: Admin, IT Admin, or Super Admin; Members cannot configure SSO. See Admin Portal roles and permissions.
Plan: Business plans displayed as Growth qualify for Enterprise SSO access; Pro and Team do not. Ineligible plans show a disabled SSO / SAML Authentication row with “Upgrade to Enterprise plan to use this feature” instead of setup controls.
Domain: At least one DNS-verified domain is required; only verified domains are used for SSO. Wispr performs one-time verification using a DNS TXT record, with no automatic re-check or token expiry.
How to configure SSO
Open admin.wisprflow.ai and sign in with a Wispr Flow admin account.
Go to Settings → Organization → User management, then find SSO / SAML Authentication.
Click Configure SSO. The setup portal opens in a new tab; follow its prompts to select your identity provider.
Create a Wispr Flow SAML application in your identity provider, using the ACS URL, entity ID, and other values the setup portal provides.
Assign the users or groups that should have access to Wispr Flow.
Complete test authentication, if prompted, with an account that exists in your identity provider and has access to the Wispr Flow SAML app.
Return to Settings → Organization → User management.
Click Refresh to check the connection manually.
The page also checks silently once per organization load, only when SSO is neither connected nor awaiting setup completion.
Configure SSO means not set up; Finish setup means inactive; Manage SSO means connected. A successful Refresh shows “Single sign-on is active.” The provider name is not displayed.
Tip: You don't need to paste XML metadata or certificates — use the prompts and links in the setup portal.
If the connection isn't active
An inactive connection shows “SSO setup is in progress. Finish setup to activate single sign-on.” A failed manual check can show “Unable to connect to your SSO provider. Check your SSO configuration and try again.”
Complete remaining setup-portal steps through Finish setup, if shown.
Check that the connection is associated with your organization and its verified domains.
Click Refresh again; Manage SSO confirms activation.
What if test authentication fails during setup?
Wait a few minutes for a new or updated SAML app to propagate, confirm the test user is assigned to the Wispr Flow SAML app, then click the sign-in button to retry.
Optional: Enforce SSO
Enforcement is off by default; connected SSO works without it. Only admins see Enforce SSO for all members, after SSO connects.
Warning: Enforcement blocks non-SSO sign-in (email/password, Google, Apple, and Microsoft) and new email/password sign-ups on the enforced domain. Existing users must switch to SSO.
Go to Settings → Organization → User management.
Enable Enforce SSO for all members.
Tell members they will sign in through your identity provider instead of email and password.
SSO enforcement and Wispr-enabled domain-access restrictions apply at sign-in only during active, trial, or past-due subscriptions—not as a condition for changing the toggle. Otherwise neither blocks sign-in; the stored SSO setting remains on and is checked at each sign-in. If either restriction check cannot be completed, sign-in is allowed rather than blocked.
If your subscription is canceled, contact support to confirm how enforcement behaves and whether it must be re-enabled when the subscription is restored.
Related access restrictions
SCIM: Configure SCIM stays disabled until SSO is connected and active. Directory sync blocks self-signup and password flows using email verification codes, independently of SSO enforcement and billing. It does not otherwise require existing users to use SSO; membership comes from the directory, not verified-domain auto-add. See Set up SCIM user provisioning.
Domain access: To block nonmembers from signing in with your domain email, even with existing accounts, contact support to have Wispr enable the restriction; admins cannot enable it themselves. Users automatically added through a verified domain are not blocked.
Approved networks
Approved-network policies can block access regardless of platform. Mac and Windows show “Your network isn't allowed”; iOS shows “Sign-in not allowed” and keeps the blocked screen after sign-out. The admin portal replaces its login form with a lockout card.
Warning: Network blocks sign users out on desktop and iOS. Desktop forced sign-out ends active dictation and clears cached organization data. iOS sign-out clears device transcripts, dictionary, notes, logs, and preferences.
Switch to an approved network.
Select Retry on the blocked screen.
Sign in again.
On desktop, a successful signed-in connection clears the block. Sign Out is also available. See network setup and recovery.
Still need help?
Contact support if:
Setup reports “This domain is already linked to another organization. Contact support.”
Test authentication still fails after you've waited and verified the SAML app configuration.
Your identity provider isn't covered by the setup portal, or you need to migrate providers or run multiple SSO connections.
Users see repeated SSO errors, unexpected redirects, or a blocked-network screen.
Include your platform, identity provider name, and the steps you've already tried.