Overview
WeGive uses the modern OpenID Connect (OIDC) / OAuth 2.0 approach to single sign-on. We do not use the older SAML-based SSO approach, so if your IT team is familiar with SAML setups, expect a slightly different (and simpler) configuration flow. Once SSO is enabled, your dashboard users will authenticate against your Entra tenant instead of using a separate WeGive password.What WeGive’s SSO does and doesn’t do
- Authentication only. WeGive uses Entra to verify who a user is, not to determine what they can do.
- No role mapping from group claims. Roles and permissions continue to be managed inside WeGive. We don’t read the
groupsclaim from your tokens. - Full just-in-time (JIT) provisioning, floored at no access. On first SSO sign-in, WeGive creates a user record from the token and automatically grants them organization membership — but with a built-in
no-accessrole that confers no actual permissions. A new SSO user can sign in and land in the dashboard, but can’t do anything there until an admin assigns a real role. The recommended flow is still to invite the user from WeGive first (with the role you want them to have) before their first SSO sign-in, so they land with real permissions immediately rather than a no-access placeholder that needs manual follow-up.
Before You Start
You’ll need:- An admin account in your Microsoft Entra tenant
- The email domain you want to use for SSO (e.g.,
yourcompany.com) - A WeGive account contact to coordinate with — SSO requires a configuration step on our end
Step 1: Register WeGive as an Application in Entra
In the Entra admin center, register a new application for WeGive with the following settings:- Redirect URI:
https://api.wegive.com/api/auth/azure/callback - Response type:
id_token - Response mode:
form_post - Scopes:
openid,profile,email
Step 2: Grant Admin Consent
This step is easy to miss but required — without admin consent, sign-in attempts will fail.- Go to the Microsoft Entra admin center at entra.microsoft.com and sign in.
- Select Identity, then Applications, then Enterprise apps.
- Search for and select the WeGive application.
- Under Manage, select API permissions.
- At the top of the API permissions page, click “Grant admin consent for [organization name]”.
- When prompted, confirm by clicking Grant.
Step 3: Send the Following Information to WeGive
Once your application is registered and admin consent is granted, securely send the following four values to your WeGive contact:tenant_idclient_idclient_secretdomain(the email domain your users will sign in with, e.g.,yourcompany.com)
Step 4: Test the Configuration
Once WeGive confirms the configuration is live, test SSO end-to-end with a single user before rolling it out broadly. To verify SSO is working:- Log out of the WeGive dashboard.
- Go to the dashboard sign-in page and enter your email address.
- When you tab from the email field to the password field, the Microsoft SSO authentication process should be triggered automatically.
- Complete the Microsoft sign-in flow.
- You should land back in the WeGive dashboard, signed in.
domain value sent to WeGive.
Adding Users After SSO Is Live
Because WeGive uses full JIT provisioning floored atno-access, here’s the recommended order of operations for adding a new dashboard user:
- Create the user in Entra (or confirm they already exist in your tenant).
- Invite the user from WeGive with the appropriate role, before their first SSO sign-in.
- The user signs in via SSO. If they were already invited with a role, that role is in place when they land in the dashboard. If they sign in without having been invited first, WeGive still creates their account and organization membership automatically — but with the no-access role, so they’ll be signed in but unable to do anything until an admin assigns a real role afterward.
Frequently Asked Questions
Does WeGive support SAML SSO? No. WeGive uses OIDC / OAuth 2.0 only. Can roles be assigned based on Entra group membership? Not today. WeGive does not read thegroups claim. Roles are assigned inside WeGive and remain there.
Can users be auto-provisioned with a role on first login? Partially. A user account and organization membership ARE created automatically on first SSO sign-in, but the membership starts with a built-in no-access role that grants nothing. Invite the user from WeGive first (before their first sign-in) so a real role is assigned from the start, rather than relying on this no-access fallback and following up manually.
What happens during the cutover when SSO is first enabled? The dashboard may be briefly unavailable to your admins while we activate the configuration. We recommend coordinating a window with your team for the activation.