SAML Single Sign On – SSO Login
View on WordPress.orgScores higher than 79% of indexed plugins
About
SAML SSO (Single Sign On) for WordPress Login with Okta, Entra ID/Azure AD, GSuite, Salesforce & All SAML IdPs. Free Unlimited SSO [24/7 Support]
Security History
What It Does
SAML Single Sign On – SSO Login connects WordPress to an external identity provider so users log in with their existing corporate or organizational credentials rather than a separate WordPress password. It supports major IdPs including Okta, Microsoft Entra ID, Azure AD/B2C, G-Suite, Shibboleth, OneLogin, Keycloak, and Salesforce, with setup handled through a guided configuration wizard. The plugin is offered by miniOrange, a vendor that also bundles additional features (such as user role mapping and attribute mapping) behind paid tiers.
Who It's For
This plugin is a fit for organizations, schools, or businesses that already use a SAML 2.0 identity provider and want employees, students, or members to access WordPress with their existing SSO credentials. It is most useful on intranets, membership sites, or any WordPress instance where centralized identity management matters more than minimizing plugin dependencies. Non-technical admins benefit from the vendor's stated 24/7 support offering.
Who Should Skip It
If your site only needs basic passwordless or social login (Google, Facebook, etc.) and you do not have an existing SAML IdP, this plugin is overkill and you will be better served by a simpler OAuth client or a basic SSO solution. Small personal blogs, brochure sites, or anyone running a single-author site without enterprise authentication requirements will gain nothing from it.
The Bottom Line
With 10,000 installs, a 98/100 user rating, and recent updates, this is a strong SAML SSO option, but the empty public support forum means you should expect to rely on miniOrange's paid support channels if you hit trouble. Free tier users may find useful functionality gated behind premium add-ons. For anyone with an existing SAML IdP who wants a guided, vendor-supported setup, it is a safe pick; everyone else can ignore it.
Related Plugins
Pick this instead if your identity provider is specifically Microsoft 365 and you also want deeper Microsoft Graph integration beyond just login.
Choose this sibling plugin instead if you need OAuth-based social login (Google, Facebook, Apple) rather than SAML 2.0.
Pick this lightweight, free, developer-focused alternative if you want SAML SSO without the miniOrange upsells and are comfortable editing config files.
Choose this instead if your environment is on-premises Active Directory / LDAP rather than a cloud SAML IdP and you need direct directory queries.
Pick this only if your institution specifically uses Shibboleth as the federated identity layer and you need a no-frills, server-side configuration approach.