
SAML 2.0 single sign-on, OAuth 2.0 for the API, role-based rights at network and group level, and short-lived access tokens revoked whenever a password changes — access control designed for a workforce that turns over quickly.
Fibi sources Speakap Single Sign-On & Access Control at no cost to you. Our advisory is funded by the carrier.
We compare Speakap against 300+ carriers so you know you're getting the best solution for your needs.
Dedicated advisor for the life of your contract — Fibi escalates issues on your behalf so you're never dealing with carrier support alone.
Accounts follow your existing identity provider rather than becoming a separate password list. For a frontline workforce this is as much an operations decision as a security one — it removes the password reset queue that otherwise lands on site managers.
Every user holds a role at network level that governs their rights across the organisation, and a separate role inside each group they belong to. Local administration is therefore possible without granting organisation-wide access.
Users and group memberships are managed by named administrators at organisation or group level rather than by implicit seniority, so it is always answerable who granted a given permission.
API authentication uses OAuth 2.0 with access tokens generated from a cryptographic random source and a one-hour lifetime, after which they must be refreshed. A leaked token has a small window rather than an indefinite one.
All active access tokens are revoked when a user changes their password — the control that makes a credential reset genuinely close off access rather than leaving live sessions running.
A minimum of ten characters with at least one lowercase, one uppercase and one non-alphabetic character, stored as salted BCrypt hashes so Speakap holds no knowledge of the actual password. Changing a password requires the existing one.
Password reset is sent as a secret link to the user's primary email address, and email addresses must be verified with a token before they can serve as primary.
With a workforce using personal devices, a lost or stolen phone is routine rather than exceptional. Remote logout and token revocation exist for it, and should be part of the documented process before it happens.
Common questions about Single Sign-On & Access Control from Speakap.
More from Speakap
A communications platform built for staff who do not sit at a desk — retail floors, kitchens, warehouses, cleaning rounds, security posts. Reaches people who have no company email account and no reason to open an intranet, which is where most internal communication quietly fails.
Your own app in the App Store and Google Play under your name and identity, with updates shipped on a fortnightly cycle. A non-branded option running under the Speakap app exists for teams that want to launch without an app-store presence, and custom domain support comes with the branded tier.
Content goes to a group, a timeline or one person, with membership and rights managed per group rather than globally. That matters at scale: a shift change at one site should not push a notification to eight hundred people at the other forty.
User accounts flow from the HR system by XML, CSV, connector or Active Directory import instead of being maintained by hand. In sectors with heavy turnover this is the difference between an accurate staff list and a directory nobody trusts after six months.