Skip to content

Single Sign-On for your entire team

Your employees sign in to oneVcard through your company account, via single sign-on. No second password, no forgotten login when someone leaves.

Why SSO matters for companies

One less login to manage, one less security risk in the company.

Sign in through your company account

oneVcard connects to your identity provider. Login happens on your side, and oneVcard never receives the password.

No second password

Employees sign in with their familiar company login. Under SSO, the email address and password can no longer be changed directly in oneVcard; everything stays centralized in the identity provider.

Verified domains

With SSO domains and verified email domains, you define which address spaces are allowed to sign in and invite. Invitations stay limited to trusted domains.

Clean offboarding

When the central account is deactivated, the person automatically loses access to oneVcard. No orphaned login, no manual cleanup in the tool.

Combinable with HR sync

SSO works hand in hand with automatic user management. Users created from Entra ID, Personio or SAP sign in directly via SSO, with no separate invitation.

One click and your team is in

Employees sign in with their familiar company account, with no extra password.

login.onevcard.app

Sign in to oneVcard

Sign in with company account
or
name@firma.de
SSO active · OpenID Connect

Set up in three steps

  1. 1

    Connect your identity provider

    We register your identity provider in your oneVcard organization. This runs standards-compliant and connects common providers such as Microsoft Entra ID.

  2. 2

    Approve SSO domains

    In the organization settings under Addons, define which email domains are allowed to sign in via SSO and which domains are trusted for invitations.

  3. 3

    Sign in with no detour

    When your team opens the app, they are directed to your company sign-in, log in with the company account and land straight in the dashboard, without a new password.

What SSO delivers at oneVcard in concrete terms

Authentication over OpenID Connect (OIDC) and SAML 2.0 against your identity provider
Standards-compliant sign-in with redirect to your company login page
Under SSO, the email address and password live in the central account, not in oneVcard
SSO domains: define which email domains are allowed to sign in
Invitation domains and verified email domains for trusted invitations
Automatic deactivation of access at offboarding via the central account
Combinable with HR sync from Entra ID, Entra ID On-Premise, Google Workspace, Personio and SAP
Automatic team assignment via user mapping, for example the Sales department into the Sales team

SSO plus automatic user management

Single Sign-On comes into its own together with provisioning and integrations.

Microsoft Entra ID

Connect your Entra ID (formerly Azure AD) as an HR source, including On-Premise. Users are created with an external ID, their email comes from the source and is locked in oneVcard.

Personio, SAP and Google Workspace

Other HR systems sync master data automatically. Through field mapping, data from the HR system flows directly into your employees' business card fields.

Rule-based team assignment

User mappings assign users to the right team automatically based on conditions from the HR system, for example the Sales department into the Sales team.

Custom domains and SSO domains

As an addon, you configure your own domain, your own favicon, SSO domains, invitation domains and verified email domains centrally in the organization settings.

Granular roles and permissions

Roles control which fields users may edit and which permissions admins have. Every new user automatically receives the unchangeable default role.

Always up-to-date data

Templates and field mappings keep business cards consistent. When something changes in the HR system, it flows through via the sync, without anyone maintaining cards by hand.

SSO in detail

Which protocol and which identity providers does oneVcard support?

oneVcard supports single sign-on over the common standards OpenID Connect (OIDC) and SAML 2.0 and connects common identity providers, including Microsoft Entra ID. When the app opens, it redirects to your company login page and, after a successful sign-in, brings you back into the app.

What happens to email and password under SSO?

Both are managed centrally in your identity provider. Under SSO, users cannot change their email address and password directly in oneVcard. Actions such as changing the email address of an invitation are also locked when the user has an external ID, because the address is sourced from the external system.

How do we prevent sign-ins from unknown addresses?

With SSO domains, you define which email domains are allowed to sign in. In addition, you set invitation domains and verified email domains so that invitations only go to trusted domains. Everything is maintained centrally in the organization settings under Addons.

What happens when an employee leaves?

When the central account is deactivated, the person automatically loses access to oneVcard without an admin having to step in manually. Combined with HR sync from Entra ID, Personio or SAP, your set of active users stays clean automatically.

Can SSO be combined with automatic user management?

Yes, that is the standard case in enterprise use. Users are created via HR sync from your system and populated with data through field mappings. User mappings assign them to the right team automatically. The users created this way then sign in directly via SSO, with no separate invitation.

Top companies rely on digital business cards from oneVcard

  • BMW
  • BASF
  • Porsche
  • expert
  • valantic
  • bitkom

Enable SSO for your company

We set up single sign-on together with your IT team, from the identity provider through the SSO domains to HR sync. Book a no-obligation call.