Skip to main content
The Security section in your organization settings embeds the WorkOS Admin Portal widgets for domain verification and SSO connection setup.

Prerequisite: Verify a domain with Wherobots

SAML-based SSO is tied to your domain. To configure SAML-based SSO with Wherobots, you must have access to edit your domain’s DNS records. Navigate to your Wherobots organization’s SSO Configuration section.

Set and verify your domain

  1. Select Add domain in the domain verification widget. The WorkOS Admin Portal opens in a new tab; enter your domain there.
  2. Add the TXT DNS record shown in the WorkOS Admin Portal to your domain provider’s DNS management portal. Use the exact record name and value provided for your domain.
  3. Wait for WorkOS to detect the record and mark your domain as verified. DNS changes may take time to propagate.

Configure SAML

Configure your Identity Provider

In the SSO Configuration section, use the SSO connection widget to open the WorkOS Admin Portal. Select your Identity Provider there and follow the provider-specific instructions to exchange metadata between your IdP and Wherobots Cloud, including any required attribute mapping.
Example
Links to some common Identity Provider documentation sites:

Enter your Identity Provider details into Wherobots Cloud

In the WorkOS Admin Portal opened from the Security section of the Wherobots Organization settings, provide your IdP metadata when prompted and complete the connection setup.

Enable SAML-based SSO

Ensure you have invited, accepted, and promoted a user to admin whose email is in the same domain as the one you are configuring SAML for. If you do not, you will be unable to do admin actions once you enable SAML-based SSO. Please contact us to disable SAML-based SSO if you run into any issues.
Once the SSO connection is active in the WorkOS-powered widget, SAML-based SSO is enforced for users with email addresses on your verified domain.

Test your SAML integration

Navigate to the login page and enter your email (with the domain you configured). Click Log In and you should be redirected to your Identity Provider. Once you complete the login process, you should be redirected back to Wherobots Cloud and see the dashboard.
Wherobots Cloud does not support Identity Provider-initiated SSO logins. You must login directly from the Wherobots Cloud login page.

Disable SAML-based SSO

Deleting the SSO connection permanently removes its configuration and sign-in records, and prevents users from signing in with your IdP. Before deleting it, make sure affected users have another sign-in method. If users rely on SSO alone, contact Wherobots Support for help with their access.

Remove the SSO connection

In the SSO Configuration section of the Security settings page, use the SSO connection widget to open the WorkOS Admin Portal. Delete the connection there and follow the prompts.
Domain removal and SSO connection removal are separate actions in the WorkOS widgets. To disable SAML-based SSO, remove the SSO connection.

Frequently Asked Questions

What is SAML?

SAML, or Security Assertion Markup Language, is a standard for exchanging authentication and authorization information between an application and an identity provider. It is commonly used in enterprise environments to authenticate users and authorize access to resources. In the context of Wherobots, SAML is used to enable users to log in to the platform using their existing identity provider.

What happens to another user’s organization at example.com when I configure SAML for example.com?

When you configure SAML for an organization and domain, any users who have previously created an account and an organization with an email from that domain will be unable to log in to those organizations. Please contact us to merge organizations and their data if required.