B2B guide & comparison

Digital Business Card with SSO: Providers with SAML 2.0, Entra ID and Automatic Provisioning Compared

If you roll out digital business cards for 50, 500 or 5,000 employees, you do not want to create and maintain them one by one. Single sign-on (SSO) and automatic user provisioning are therefore the decisive criterion as soon as a digital business card grows from an individual product into an enterprise solution: employees sign in with their familiar Microsoft or Google account, new colleagues receive their card automatically during onboarding, and when they leave, access is revoked centrally.

This comparison shows which providers implement SSO via SAML 2.0 and Microsoft Entra ID (formerly Azure AD) cleanly, how automatic provisioning works and what IT and data protection departments in Germany should look out for. According to our methodology, oneVcard, Spreadly and Lemontaps lead the field, with different strengths in SSO, hosting and integration depth.

Recommended providers for this use case

Sorted by overall score; the category-relevant sub-score is also shown per provider.

1

oneVcard

91 /100

Overall winner in the comparison: an ISO 27001 certified data center in NΓΌrnberg, hosting and development exclusively in Germany, full enterprise package with SSO, user provisioning and dedicated signature management.

4.9 βŒ€ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 88/100

2

Spreadly

88 /100

Customer data on Hetzner in Germany according to the provider, delivery via EU infrastructure (including Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS), second-strongest GDPR score in the test (92); comparatively young company (founded 2022).

4.4 βŒ€ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 88/100

3

Lemontaps

87 /100

German enterprise competitor from Stuttgart with its own ISO 27001 certification (TÜV SÜD) and hosting on AWS Frankfurt.

4.8 βŒ€ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 82/100

4

Tapni

82 /100

Strong B2B provider with Frankfurt hosting and a broad enterprise feature set, though headquarters and development sit outside Germany

4.6 βŒ€ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 78/100

5

baningo cards

78 /100

Privacy-focused team solution from Austria with hosting in German ISO 27001 data centers

4.5 βŒ€ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 54/100

6

wazzl

77 /100

Privacy-focused digital business card from Bavaria: in-house German hosting to ISO 27001, SAML SSO and API, with limited pricing transparency.

  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 64/100

7

Blinq

76 /100

Australian market leader with top ratings and strong enterprise technology, but without guaranteed EU hosting.

4.8 βŒ€ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 80/100

8

HiHello

76 /100

US provider with a deep enterprise feature set and top ratings, but purely US hosting.

4.7 βŒ€ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 76/100

9

Popl

75 /100

US provider with strong integration and enterprise depth, but data storage in the USA/Canada and USD pricing.

4.5 βŒ€ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 80/100

10

Uniqode (ehemals Beaconstac)

75 /100

US enterprise platform (formerly Beaconstac) with SOC 2, ISO 27001 and SCIM, but without EU hosting

4.5 βŒ€ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 82/100

11

Mobilo

68 /100

US provider with a strong sales focus and an EU hosting option, but a thin GDPR and review situation

2.3 βŒ€ external
  • EU hosting available

Enterprise Integration (SSO/SCIM/MDM/API): 72/100

What SSO, SAML 2.0, Entra ID and SCIM specifically mean

Single sign-on (SSO) means: employees sign in once centrally, for example via the company account, and thereby use additional applications, here the digital business card, without a separate password. Technically, this usually runs via SAML 2.0 (Security Assertion Markup Language), an established industry standard with which the identity provider (e.g. Microsoft Entra ID, formerly Azure Active Directory, or Google Workspace) confirms the identity to the business application.

Provisioning has to be distinguished from the login itself: it creates user accounts automatically, updates them and deactivates them again. The open standard for this is called SCIM (System for Cross-domain Identity Management).

In practice, however, the same effect can also be achieved via an HR or directory sync, for example directly from Entra ID or a personnel system, so that joiners and leavers are automatically reflected in the card management. For IT teams, what ultimately counts is the result: an automatic user lifecycle from onboarding to offboarding, without manual list maintenance.

oneVcard: SSO pioneer with SAML 2.0, Entra ID and automatic provisioning

oneVcard (oneVcard GmbH) takes first place in this category. The provider supports SSO via SAML 2.0 as well as Microsoft Entra ID / Azure AD and Google Workspace directly.

Automatic user provisioning is available: accounts are provisioned in a SCIM-like manner via the Entra ID connection or the HR sync and revoked again when an employee leaves. The complete user lifecycle thus runs without manual maintenance.

In addition, oneVcard offers more than 20 integrations, including Entra ID, Google Workspace, SAP, Personio, BambooHR, Salesforce, HubSpot and Dynamics 365, as well as an open REST API in the Enterprise plan. An MDM device rollout via Microsoft Intune is not publicly documented and should be confirmed with the provider before signing a contract.

On data protection, oneVcard scores with operation in an ISO 27001 certified data center in Nuremberg: hosting and development take place exclusively in Germany, without transfer to third countries. This is complemented by a DPA under Art. 28 GDPR on request, an external data protection officer, daily backups, 2FA and regular penetration tests.

The Premium plan is a paid plan (annual billing); Teams and Teams Enterprise conditions including SSO are individual.

Spreadly and Lemontaps: strong SSO alternatives with ISO 27001 certification

Spreadly (Spreadly GmbH, near MΓΌnchen) likewise relies consistently on enterprise standards: SSO via SAML 2.0 and OAuth 2.0, SCIM provisioning as well as bulk onboarding via CSV, Azure AD and Google Workspace. The HRIS connection to Personio and BambooHR as well as CRM integrations round out the package.

According to the provider, customer data is stored at Hetzner in Germany; delivery runs via Bunny CDN among others, the company is certified to ISO 27001:2022 and provides a DPA; the Professional plan is a paid plan per user per month, Enterprise with SSO is individual. Lemontaps (Lemon Innovation & Technology GmbH, Stuttgart) brings SSO via SAML 2.0, Azure/Entra ID and Okta as well as native SCIM provisioning, plus audit logs, white labeling and a REST API in the Enterprise plan.

Lemontaps also hosts exclusively in Germany (AWS Frankfurt) and is certified to ISO/IEC 27001 by TÜV SÜD. In independent user reviews, Lemontaps leads with very good scores (OMR approx. 4.8/5, Trustpilot approx. 4.7/5). The Pro plan is a paid plan per user per month, Team and Enterprise prices are available on request.

Selection criteria: what IT and data protection should really watch for with SSO

In a comparison, more counts than the question of whether SSO is available at all. First: does the SSO mechanism fit your own identity provider? SAML 2.0 is considered the standard, but the specific connection to Microsoft Entra ID or Google Workspace should be documented and tested.

Second: how does provisioning work, via SCIM, via an HR or directory sync or via the API? What matters is that joiners and leavers are mapped automatically. Third: in which plan is SSO included? With all three top providers, SSO belongs in the Teams or Enterprise tier with individual pricing.

Fourth, often decisive for German companies, data storage: a German hosting provider with a data center in Germany and a DPA under Art. 28 GDPR is legally easier to handle than a US cloud, which requires additional safeguards for the third-country transfer. oneVcard (an ISO 27001 data center in Nuremberg), Spreadly (Hetzner, ISO 27001:2022) and Lemontaps (AWS Frankfurt, ISO/IEC 27001) each fulfill this criterion with hosting exclusively in Germany.

Frequently asked questions

What is the difference between SSO and automatic provisioning?

SSO (single sign-on) governs the login: employees log in with their central company account, without a separate password for the digital business card. Automatic provisioning, on the other hand, governs the lifecycle of the accounts.

It creates users automatically during onboarding, updates them and revokes access when an employee leaves. This is implemented via the SCIM standard or via an HR or directory sync, for example from Microsoft Entra ID. For a smooth rollout, you usually need both.

Which digital business card provider offers the best SSO?

According to our methodology, oneVcard leads the SSO category: SAML 2.0, Microsoft Entra ID / Azure AD and Google Workspace are supported, plus automatic provisioning (SCIM-like via the Entra ID connection or the HR sync). An MDM device rollout based on Intune is not publicly documented and should be confirmed with the provider.

Spreadly (SAML 2.0, OAuth 2.0, SCIM) and Lemontaps (SAML 2.0, Entra ID, Okta, native SCIM) are also strong alternatives with ISO 27001 certification. In independent user reviews, Lemontaps performs best.

Do the providers support Microsoft Entra ID (Azure AD)?

Yes. oneVcard connects Microsoft Entra ID / Azure AD directly for SSO and automatic user provisioning; an MDM device rollout via Microsoft Intune and Entra is not publicly documented and should be confirmed with the provider before signing a contract. Spreadly enables bulk provisioning via Azure AD and Google Workspace, Lemontaps supports SSO via SAML 2.0, Azure/Entra ID and Okta.

All three top providers are therefore suitable for Microsoft 365 environments.

Is SSO included in all plans?

As a rule, no. With digital business cards, SSO is typically an enterprise feature. With oneVcard, SSO belongs in the Teams Enterprise tier (individual conditions), with Spreadly in the Enterprise plan (from approx. 1,000 employees) and with Lemontaps likewise in the Enterprise plan. The individual and Premium plans (e.g. the oneVcard Premium plan) do not include SSO.

Why is a German hosting provider relevant for SSO solutions?

With SSO and provisioning, identity and personnel data flow between the identity provider and the card management. If this data is processed exclusively at a German hosting provider with a data center in Germany, the third-country problem, which requires additional safeguards with US clouds, does not arise.

A DPA under Art. 28 GDPR is mandatory. oneVcard hosts in an ISO 27001 certified data center in Nuremberg, Spreadly hosts at Hetzner (ISO 27001:2022), Lemontaps on AWS Frankfurt (ISO/IEC 27001), each exclusively in Germany.

What is SCIM and do I absolutely need it?

SCIM (System for Cross-domain Identity Management) is an open standard for automatically creating, updating and deactivating user accounts between systems. The SCIM standard is not strictly required. What matters is that automatic provisioning works.

This can also be done via an HR or directory sync, as with oneVcard via the Entra ID connection. Spreadly and Lemontaps additionally use classic SCIM. In practice, what counts is the result: an automatic user lifecycle without manual maintenance.

Ad

Request a direct consultation with the test winner

Planning a company-wide rollout of digital business cards? Request a free, no-obligation consultation with our test winner oneVcard.

Key criteria (multiple choice)