[{"question":{"category_id":1368782,"account_id":12867,"created_at":"2026-05-22T17:31:29.491Z","tag_names":["azure ad","biller genie security","duo sso","enterprise authentication","entra id","federated identity","google workspace sso","jumpcloud sso","oidc","okta biller genie","openid connect","saml","single sign on","sso","sso not supported","sso roadmap"],"answer_sample":"A short, honest answer to one of the most common security-evaluation questions we","long_answer_sample":"A short, honest answer to one of the most common security-evaluation questions we get from larger and enterprise merchants: does Biller Genie support Single Sign-On (SSO) via SAML or OpenID Connect? Current status: SSO is not supported today Biller Genie does not currently support SAML, OpenID Connect, or other federated identity providers (Okta, Az","language_id":1,"id":3826929,"last_published_date":"May 30th, 2026","last_published_avatar":"\u003cimg class=\"avatar circle\" width=\"96\" height=\"96\" style=\"background: url(\u0026quot;/initials_avatars/TA?bg=e0633a\u0026amp;s=192\u0026amp;fg=fff\u0026quot;) 0% 0% / 96px 96px;\" src=\"https://secure.gravatar.com/avatar/841e7ea85ebda058cdd7ee30638e7bee.png?s=96\u0026amp;d=blank\" /\u003e","last_published_user_name":"Thomas Aronica","indexable_body":"short, honest answer one common security-evaluation questions get larger enterprise merchants biller genie support single sign-on (sso) via saml openid connect current status sso supported today currently saml, connect, federated identity providers (okta, azure ad / entra id, google workspace sso, duo jumpcloud, etc.). every user authenticates genie-managed username (email address) password, plus optional per-user two-factor authentication. applies plan tiers, including premium plans granular role permissions. authentication can enable time-based one-time password (totp) back recovery codes. totp works authenticator, microsoft authy, 1password, rfc 6238-compliant authenticator. see setting . limitation 2fa opt-in per user. org-level toggle require everyone. security policy mandates account, need walk enabling it. role-based permissions plans, offers seven (super user, settings manager, add-ons installer/configurator, subscription editor, dashboard viewer, report viewer) give fine-grained control system. managing users session controls auto-logout 25 minutes inactivity production. sessions persisted longer this. logs requirements enforced platform level — minimum length, complexity, check known breached passwords. immediate invalidation disabled user's next api call page request denied, browser tab open. requires practical options take team asking use manager (1password, dashlane, bitwarden business, lastpass business) centralize credential management. combined genie, gives operational benefits central rotation, revocation employee leaves, audit visibility credentials. disable departing employees immediately. revokes access invalidates equivalent scim deprovisioning surface area expose. list quarterly active roster. will future roadmap most-requested features customers. committed timeline. organization needs adopt expand contact support@billergenie.com customer ask gets logged feature weighed planning, let know if/when becomes available beta. related articles codes multi-factor (session security)","name":"Single Sign-On (SSO / SAML) — Current Status","votes":0,"is_published":true,"slug":"single-sign-on-sso-status","first_category":"Control Panel \u0026 Settings","categories_display_for_views":"Control Panel \u0026 Settings","parent_categories":[1368782],"is_internal":false,"is_private":false,"extra_categories":[],"url":"/settings-and-account/single-sign-on-sso-status?from_search=235632918","host":"https://helpcenter.billergenie.com","body_txt":"short, honest answer one common security-evaluation questions get larger enterprise merchants biller genie support single sign-on (sso) via saml openid connect current status sso supported today currently saml, connect, federated identity providers (okta, azure ad / entra id, google workspace sso, duo jumpcloud, etc.). every user authenticates genie-managed username (email address) password, plus optional per-user two-factor authentication. applies plan tiers, including premium plans granular role permissions. authentication can enable time-based one-time password (totp) back recovery codes. totp works authenticator, microsoft authy, 1password, rfc 6238-compliant authenticator. see setting . limitation 2fa opt-in per user. org-level toggle require everyone. security policy mandates account, need walk enabling it. role-based permissions plans, offers seven (super user, settings manager, add-ons installer/configurator, subscription editor, dashboard viewer, report viewer) give fine-grained control system. managing users session controls auto-logout 25 minutes inactivity production. sessions persisted longer this. logs requirements enforced platform level — minimum length, complexity, check known breached passwords. immediate invalidation disabled user's next api call page request denied, browser tab open. requires practical options take team asking use manager (1password, dashlane, bitwarden business, lastpass business) centralize credential management. combined genie, gives operational benefits central rotation, revocation employee leaves, audit visibility credentials. disable departing employees immediately. revokes access invalidates equivalent scim deprovisioning surface area expose. list quarterly active roster. will future roadmap most-requested features customers. committed timeline. organization needs adopt expand contact support@billergenie.com customer ask gets logged feature weighed planning, let know if/when becomes available beta. related articles codes multi-factor (session security)","categories":{"current":{"id":1368782,"name":"Control Panel \u0026 Settings","url":"/settings-and-account"}},"category_param":"settings-and-account"}}]