Configure SSO

Last updated: September 4, 2026

Available on: Configured in a web browser at admin.wisprflow.ai. SSO sign-in works on Mac, Windows, iOS, and Android; IP allowlist enforcement is desktop-only.

Let your team sign in to Wispr Flow with your company's identity provider. Configure SAML single sign-on (SSO) in the admin portal in under 10 minutes.


Before you start

  • Access to your identity provider (for example, Okta, Microsoft Entra ID, or Google Workspace), with permission to create a SAML application in it.

  • An Admin or IT Admin role in your Wispr Flow organization. Members cannot configure SSO.


How to configure SSO

  1. Open admin.wisprflow.ai and sign in with a Wispr Flow admin account.

  2. Go to Settings → Organization → Authentication. A Configure SSO button means SSO isn't set up yet.

  3. Click Configure SSO. The setup portal opens in a new tab; follow its prompts to select your identity provider.

  4. Create a Wispr Flow SAML application in your identity provider, using the ACS URL, entity ID, and other values the setup portal provides.

  5. Assign the users or groups that should have access to Wispr Flow.

  6. Complete test authentication, if prompted, with an account that exists in your identity provider and has access to the Wispr Flow SAML app.

  7. Return to Settings → Organization → Authentication and click Refresh. Your identity provider name and a connected status confirm SSO is live.

Tip: You don't need to paste XML metadata or certificates — use the prompts and links in the setup portal.

Important: If Refresh reports the connection is not active, finish the remaining setup portal steps and click Refresh again. If it returns "SSO not connected," verify the connection is associated with your organization.

Note: SCIM provisioning stays disabled until SSO is connected and active.


Optional: Enforce SSO (Flow Business and Enterprise)

Enforce SSO requires all members to sign in with your identity provider. It is off by default.

  1. Go to Settings → Organization → Authentication.

  2. Enable the Enforce SSO for all members toggle. It appears only after SSO is connected and requires an active Flow Business or Flow Enterprise subscription.

  3. Tell members they will sign in through your identity provider instead of email and password.

Warning: Enforce SSO blocks all non-SSO sign-in methods (email/password, Google, Apple, and Microsoft) for users on the enforced domain. Existing users must switch to SSO.

  • Enforcement stays active while your Business or Enterprise subscription is in good standing, including during a trial or a brief past-due period.

  • If your subscription is canceled, contact support to confirm how enforcement behaves and whether it must be re-enabled when the subscription is restored.


IP allowlist and network restrictions

Enterprise admins can restrict Wispr Flow access to specific networks with an IP allowlist at Settings → Organization → Network access. A user who connects from a network that isn't on the approved list is signed out and shown a lockout screen.

Note: Network access is visible only to Enterprise customers who have had the feature enabled by Wispr. Enforcement works on Mac and Windows. On Android, users on non-allowed networks are not signed out and see no lockout screen.

  • Wildcard CIDRs (0.0.0.0/0, ::/0) are not accepted.

  • To disable the allowlist, remove the setting entirely — an empty list is not allowed.

  • A self-lockout safeguard requires your current IP to be within the existing allowlist before a change or removal applies.

  • A blocked user's lockout screen dismisses on their next successful sign-in from an allowed network.

  • A locked-out admin can look up their current egress IP by visiting the admin portal from a non-restricted network, then add that address to the allowlist.


FAQs

What if test authentication fails during setup?

Wait a few minutes for a new or updated SAML app to propagate, confirm the test user is assigned to the Wispr Flow SAML app, then click the sign-in button to retry.

Can users sign in from their identity provider dashboard?

Yes. Wispr Flow supports SP-initiated login (from the Wispr Flow login screen) and IdP-initiated login (clicking the Wispr Flow tile in a dashboard such as Okta or Microsoft Entra ID).

Where do users find the SSO sign-in option on each platform?

Under enforced SSO, users sign in with the work email that matches your identity provider. The entry point differs by platform:

  • Mac and Windows: Click Sign in via browser, then enter your work email address.

  • Android: Tap Continue with SSO and enter your work email address. If the app loses track of the browser session, a "Finish signing in" screen appears with a "Try again" button.

  • iOS: Tap More Options, then Continue with SSO, and enter your work email address. If that email is already registered with an OAuth provider, the email screen offers "Continue with <provider>" instead of a password field.

What if users complete IdP login but don't return to Wispr Flow?

Check that your firewall allows redirects from your identity provider back to Wispr Flow, and ask affected users to retry with VPN disabled or on a different network.

  • Windows: Make sure only one instance of Wispr Flow is running, so the browser sign-in lands in the right place.

  • Mac and Windows: If browser sign-in isn't completed promptly, the desktop login screen stops waiting — click Sign in via browser again.

What if the SSO login page can't reach the server before redirecting to the identity provider?

If a corporate egress proxy or security filter blocks the admin portal login page from reaching Wispr's servers, the page proceeds directly to your SSO provider's sign-in page as long as your device reports being online, and the flow completes normally.

An error is shown and the login page stays open if the server responds with an error (such as an authentication or server error), or the device is fully offline.

Why can't users sign in with email/password or Google/Apple/Microsoft after SCIM is enabled?

SCIM only blocks new account creation for users on your domain who don't already have an account; they must be provisioned through SCIM and sign in via SSO. To require SSO for everyone, enable both SCIM and Enforce SSO.

  • With SCIM enabled, adding, removing, and inviting members is locked in the admin portal, which returns: "User management is controlled by your identity provider via SCIM. Please add or remove users through your identity provider." Make those changes in your identity provider.

  • Deleting a SCIM-provisioned user in the IdP also revokes any pending invitations for them.

  • Provisioning is limited by your enterprise seat cap. After freeing a seat, re-trigger provisioning from the identity provider (for example, unassign and reassign the user).

What is the difference between Enforce SSO and Restrict Domain Access?

Enforce SSO requires all users on your domain to sign in via SSO instead of email/password or social login. Restrict Domain Access blocks anyone outside your organization from signing in with your domain email, even if they already have an account; contact support to have Wispr enable it.

Users who would be auto-added to your organization based on a verified domain are not blocked.

What if users see "Your network isn't allowed"?

On Mac and Windows, the user connected from a network that isn't on your IP allowlist, so they were signed out and shown a lockout screen with Retry and Sign out.

  • Check Settings → Organization → Network access and confirm all expected office IPs, VPN exit IPs, and remote locations are included.

  • Retry re-opens browser sign-in and blocks again if the user is still on a disallowed network; from an allowed network it may sign them straight back in. Sign out clears the blocked state and forces the login form.

For full troubleshooting, see Login Issues with Wispr Flow.

Who should be assigned the IT Admin role?

IT staff who manage SSO, billing, or team settings but don't dictate with Wispr Flow. IT Admins don't use a dictation seat and don't count toward the organization seat cap. Assign the role from the role dropdown in the member table, or when inviting a new member; SCIM cannot assign IT Admin, so provisioned users arrive as Member.

An IT Admin who opens the desktop app sees a modal titled "You cannot use Wispr Flow as an IT Admin" with Sign out and Go to Admin Portal options. If their seat is upgraded to Admin, the modal clears when focus returns to the app — no sign-out needed.

Why does my iOS SSO or OAuth sign-in show a generic error?

On iOS, cancelling the browser sheet shows no error, and all other SSO and OAuth failures show a single generic "Error" alert that doesn't identify the cause. Email sign-in errors are more specific: incorrect email or password, connection error, sign-in failed, or unknown error.


Limitations and notes

  • Enforce SSO and Restrict Domain Access require an active Flow Business or Flow Enterprise subscription.

  • The SSO setup portal supports a wide range of identity providers, including Okta, Microsoft Entra ID (Azure AD), and Google Workspace.

  • Session refreshes are automatic and silent. If a session cannot be refreshed (for example, the IdP session was revoked or expired), users are signed out, which ends any active dictation, clears cached org data, and requires re-authentication in the browser.


Still need help?

Reach out to our support team if:

  • Test authentication still fails after you've waited and verified the SAML app configuration.

  • Your identity provider isn't covered by the setup portal, or you need to migrate providers or run multiple SSO connections.

  • Users see repeated SSO errors, unexpected redirects, or "Your network isn't allowed."

Include your platform, identity provider name, and the steps you've already tried. Most SSO setup issues are resolved in one reply.