Speakap
Speakap
Service Detail

Single Sign-On & Access Control — Speakap

SAML 2.0 single sign-on, OAuth 2.0 for the API, role-based rights at network and group level, and short-lived access tokens revoked whenever a password changes — access control designed for a workforce that turns over quickly.

Free Advisory

Fibi sources Speakap Single Sign-On & Access Control at no cost to you. Our advisory is funded by the carrier.

Side-by-Side Comparison

We compare Speakap against 300+ carriers so you know you're getting the best solution for your needs.

Post-Sale Support

Dedicated advisor for the life of your contract — Fibi escalates issues on your behalf so you're never dealing with carrier support alone.

Key Features

SAML 2.0 single sign-on

Accounts follow your existing identity provider rather than becoming a separate password list. For a frontline workforce this is as much an operations decision as a security one — it removes the password reset queue that otherwise lands on site managers.

Roles at two levels

Every user holds a role at network level that governs their rights across the organisation, and a separate role inside each group they belong to. Local administration is therefore possible without granting organisation-wide access.

Administrators are designated

Users and group memberships are managed by named administrators at organisation or group level rather than by implicit seniority, so it is always answerable who granted a given permission.

Short-lived API tokens

API authentication uses OAuth 2.0 with access tokens generated from a cryptographic random source and a one-hour lifetime, after which they must be refreshed. A leaked token has a small window rather than an indefinite one.

Password change revokes everything

All active access tokens are revoked when a user changes their password — the control that makes a credential reset genuinely close off access rather than leaving live sessions running.

Password policy enforced by the platform

A minimum of ten characters with at least one lowercase, one uppercase and one non-alphabetic character, stored as salted BCrypt hashes so Speakap holds no knowledge of the actual password. Changing a password requires the existing one.

Verified email for recovery

Password reset is sent as a secret link to the user's primary email address, and email addresses must be verified with a token before they can serve as primary.

Losing a phone is a handled case

With a workforce using personal devices, a lost or stolen phone is routine rather than exceptional. Remote logout and token revocation exist for it, and should be part of the documented process before it happens.

Frequently Asked Questions

Common questions about Single Sign-On & Access Control from Speakap.