Skip to content

SAML

Sign in to Wise using single sign-on (SSO) with your SAML 2.0 identity provider. Wise acts as the SAML service provider.

These endpoints follow the SAML 2.0 Web Browser SSO Profile. They are part of a browser-based sign-in flow and are not general-purpose REST API endpoints, so they do not use API tokens.

SAML SSO requires configuration on the Wise side. To enable it for your integration, contact your Wise implementation team.

To set up SSO, configure Wise as a service provider in your identity provider using the service provider metadata. After you authenticate, your identity provider sends the SAML response to the Assertion Consumer Service endpoint.

Assertion Consumer Service (ACS)

Request

Receives the SAML authentication response from your identity provider after you authenticate.

The identity provider sends a SAMLResponse to this endpoint using the SAML HTTP POST binding. The response is validated and, if successful, completes your SAML sign-in.

This endpoint implements the SAML 2.0 Web Browser SSO Profile. For details of the SAML message format and protocol requirements, refer to the OASIS SAML 2.0 specification.

Headers
X-External-Correlation-Idstring, (uuid), <= 36 characters

Optional UUID for correlating requests across systems. If provided, Wise echoes it back in the response. Maximum 36 characters. Learn more.

Example:f47ac10b-58cc-4372-a567-0e02b2c3d479
Bodyapplication/x-www-form-urlencodedrequired
SAMLResponsestringrequired

Base64-encoded SAML <samlp:Response> message issued by the identity provider.

RelayStatestring

Opaque state value. If the authentication request included a RelayState, the identity provider returns it unchanged.

curl -i -X POST \
  https://api.wise.com/2026Q4/login/saml2/sso \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -H 'X-External-Correlation-Id: f47ac10b-58cc-4372-a567-0e02b2c3d479' \
  -d SAMLResponse=string \
  -d RelayState=string

Responses

The SAML response was processed. Your browser is redirected to continue the sign-in flow.

Headers
Locationstring

URL your browser is redirected to.

X-External-Correlation-Idstring, (uuid), <= 36 characters

Echoed back when X-External-Correlation-Id was included in the request. Learn more.

Example:"f47ac10b-58cc-4372-a567-0e02b2c3d479"
x-trace-idstring

Unique trace identifier assigned by Wise. Useful when contacting support about a specific request.

Example:"fba501b6d453b96789f52338f019341f"
Response
No content