SAML and SSO for managers
VisibleHours stores one SAML 2.0 connection per organization: a metadata URL, issuer, signing certificate, and identity-provider SSO URL, plus the ACS and Entity ID your provider needs. There is no OpenID Connect path — not OIDC, not just-in-time provisioning, no passwordless or magic-link sign-in, and no named-vendor certification badge. An identity provider works here when it publishes SAML 2.0 EntityDescriptor metadata with a signing certificate — not because every directory on the internet is supported.
Test fetches that document and copies issuer, certificate, and SSO URL when they are present. Enable the connection when operations is ready. ACS then accepts an HTTP-POST signed assertion, maps the email to a manager who already exists in that organization, and issues a session. If a live provider is not set, sample metadata is test mode — a VisibleHours demo IdP, not a live directory. The connection tip on the signed-in SSO screen is a VisibleHours reading of your row, not a live language model.
Public Search on this site stays here. It will not set up SSO for your company, open the signed-in SSO screen, or claim a vendor badge. After you sign in, Ask “sso”, “saml”, “single sign-on”, “open sso”, or “configure sso” opens SSO. Ask “copy acs url” opens /sso#acs. Ask “paste metadata” opens /sso#idp. Ask “test metadata” or “enable sso” opens /sso#test. Ask “how to set up sso”, “sso tutorial”, or “saml tutorial” opens the signed-in tutorial. Ask “login tutorial” or “password or SAML” opens the sign-in tutorial. Ask “works with every IdP”, “openid connect”, “just-in-time provisioning”, “passwordless magic link SSO”, or a named-vendor certification is refused.
- Sign in with email and password the first time. Open SSO / SAML. Ask “open sso” or “configure sso” after you are in.
- Copy Entity ID and the ACS URL for the identity-provider admin. ACS is HTTP-POST only. Download SP metadata if the provider wants an XML file.
- Paste a metadata URL, or paste issuer and certificate yourself, or use the VisibleHours sample to walk ACS without a live directory.
- Press Test. Enable. Managers use Sign in with SAML and the organization slug on the login page. Password sign-in still works.
What this is not
- Not OpenID Connect. SAML 2.0 metadata and a signed assertion are what ACS accepts.
- Not passwordless or magic-link sign-in. Managers still have an email and password.
- Not an identity-provider certification or a named-vendor security badge.
- Not every identity provider. The IdP must publish SAML 2.0 EntityDescriptor metadata with a signing certificate (or you paste issuer and certificate yourself).
- Not just-in-time provisioning. ACS maps the assertion email to a manager who already exists in that organization.
- Not a change to the Windows tray or employee invite codes. SSO is for managers.
- Not outreach. VisibleHours does not email your provider from this screen.
- Sample metadata is a VisibleHours demo IdP, not a live directory.
- Not a done-for-you setup. Public Search will not set up SSO for your company.
Public guide: SAML / SSO ACS login for managers. Signed-in steps: SSO tutorial. Seats stay $7 / seat on Pricing — this page does not start checkout.