Skip to main content
Administrator Guide
Last Updated: 2026-07-24
Concept: Workday Wellness Single Sign-On Links

Concept: Workday Wellness Single Sign-On Links

Workday Wellness single sign-on (SSO) links enable workers to securely connect with a benefit provider without requiring a separate login. You can use SSO links to provide authenticated access within:
  • Worker communication cards
  • Benefit enrollments
  • Business process steps.
Example: You can embed an SSO link on the Benefits and Pay Hub so workers can access a third-party wellness application during open enrollment.
Wellness partners use an API to stage a SAML SSO link on your behalf. This automated API integration replaces manually configured SAML SSO links.
When a partner stages an SSO link:
  • The API creates a proposed configuration directly in your tenant.
  • Workday secures the cross-system connection at both the tenant and partner levels.
  • Workday notifies security administrators to review the request.
  • The link remains inactive until an administrator approves it.
When you review the request, you can approve or deny the staging proposal. If you approve the request Workday notifies the partner with the new SSO metadata details so they can utilize the connection.
When partners configure an SSO link, they use 1 of these dynamic attribute values to validate the user:
  • Email address
  • Employee ID
  • Username
  • Workday identifier