B2B guide & comparison

Digital Business Card with SSO: Providers with SAML 2.0, Entra ID and Automatic Provisioning Compared

Anyone rolling out digital business cards to 50, 500 or 5,000 employees does not want to create and maintain them one by one. Single sign-on (SSO) and automatic user provisioning are therefore the decisive criteria as soon as a digital business card moves from an individual product to an enterprise solution: employees log in with their familiar Microsoft or Google account, new colleagues automatically receive their card during onboarding, and access is centrally revoked when they leave.

This comparison shows which providers cleanly implement SSO via SAML 2.0 and Microsoft Entra ID (formerly Azure AD), how automatic provisioning works, and what IT and data protection departments in Germany should look out for. According to our methodology, oneVcard, Spreadly and Lemontaps lead the field – with different strengths in SSO, hosting and depth of integration.

Recommended providers for this use case

Sorted by overall score; the category-relevant sub-score is also shown per provider.

1

oneVcard

92 /100

Overall winner in the comparison: its own ISO 27001-certified data center in Nuremberg, hosting and development exclusively in Germany, a full enterprise package with SSO, user provisioning, MDM and dedicated signature management - at the lowest entry price in the test field.

  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 92/100

2

Spreadly

87 /100

Customer data on Hetzner in DE per the vendor, delivery via EU infrastructure (incl. Bunny CDN), ISO 27001:2022, full enterprise provisioning (SSO/SCIM/HRIS) - second-highest GDPR score in the test (92), but a young company without independently verified user reviews.

  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 84/100

3

Lemontaps

85 /100

German enterprise competitor from Stuttgart with its own ISO 27001 certification (TÜV SÜD) and hosting on AWS Frankfurt.

4.7 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 82/100

4

Tapni

82 /100

B2B-strong provider with Frankfurt hosting and a broad enterprise feature set – but company headquarters and development are located outside Germany

4.6 ⌀ external
  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 78/100

5

Blinq

75 /100

Australian market leader with top ratings and strong enterprise technology, but without guaranteed EU hosting.

4.8 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 80/100

6

HiHello

75 /100

US provider with a deep enterprise feature set and top ratings, but pure US hosting.

4.7 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 76/100

7

wazzl

75 /100

Privacy-focused digital business card from Bavaria: own German hosting under ISO 27001, SAML SSO and API, with limited price transparency.

  • DE server location

Enterprise Integration (SSO/SCIM/MDM/API): 64/100

8

Popl

73 /100

US provider with strong integration and enterprise depth, but data hosting in the USA/Canada and USD pricing.

4.5 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 80/100

9
72 /100

US enterprise platform (formerly Beaconstac) with SOC 2, ISO 27001 and SCIM - but no EU hosting

4.5 ⌀ external
  • Hosting outside EU

Enterprise Integration (SSO/SCIM/MDM/API): 82/100

10

Mobilo

66 /100

US provider with a strong sales focus and an EU-hosting option, but a thin GDPR and reviews picture

2.3 ⌀ external
  • EU hosting available

Enterprise Integration (SSO/SCIM/MDM/API): 72/100

What SSO, SAML 2.0, Entra ID and SCIM concretely mean

Single sign-on (SSO) means: employees log in once centrally – for example via the company account – and use additional applications without a separate password, in this case the digital business card. Technically, this usually runs via SAML 2.0 (Security Assertion Markup Language), an established industry standard with which the identity provider (e.g. Microsoft Entra ID, formerly Azure Active Directory, or Google Workspace) confirms the identity to the specialist application.

Provisioning must be distinguished from the login itself: it automatically creates user accounts, updates them and deactivates them again. The open standard for this is called SCIM (System for Cross-domain Identity Management).

In practice, however, the same effect can also be achieved via an HR or directory sync – for example directly from Entra ID or a personnel system – so that new hires and departures are automatically reflected in card management. For IT teams, what ultimately counts is the result: an automatic user lifecycle from onboarding to offboarding, without manual list maintenance.

oneVcard: SSO pioneer with SAML 2.0, Entra ID and automatic provisioning

oneVcard (oneVcard GmbH) takes first place in this category. The provider supports SSO via SAML 2.0 as well as Microsoft Entra ID / Azure AD and Google Workspace directly.

Automatic user provisioning is available: accounts are provisioned in a SCIM-like manner via the Entra ID connection or the HR sync and revoked again when employees leave – the entire user lifecycle thus runs without manual maintenance. In addition, oneVcard supports MDM rollouts on a Microsoft Intune / Entra basis (e.g. distribution of wallet cards or the app) and offers more than 20 integrations, including Entra ID, Google Workspace, SAP, Personio, BambooHR, Salesforce, HubSpot and Dynamics 365, as well as an open REST API in the Enterprise plan.

On data protection, oneVcard scores with operation in its own, ISO 27001-certified data center in Nuremberg: hosting and development take place exclusively in Germany, without transfer to third countries. This is complemented by a data processing agreement (DPA) under Art. 28 GDPR on request, an external data protection officer, daily backups, 2FA and regular penetration tests.

The Premium plan is paid (annual billing); Teams and Teams Enterprise terms including SSO are individual.

Spreadly and Lemontaps: strong SSO alternatives with ISO 27001 certification

Spreadly (Spreadly GmbH, near Munich) likewise consistently relies on enterprise standards: SSO via SAML 2.0 and OAuth 2.0, SCIM provisioning as well as bulk onboarding via CSV, Azure AD and Google Workspace. The HRIS connection to Personio and BambooHR as well as CRM integrations round off the package.

Customer-data hosting is with Hetzner in Germany per the vendor (CDN/edge incl. Bunny), the company is certified to ISO 27001:2022 and provides a data processing agreement (DPA) under Art. 28 GDPR; the Professional plan is paid per user/month, Enterprise with SSO is individual.

Lemontaps (Lemon Innovation & Technology GmbH, Stuttgart) brings SSO via SAML 2.0, Azure/Entra ID and Okta as well as native SCIM provisioning – plus audit logs, white labeling and a REST API in the Enterprise plan. Lemontaps also hosts exclusively in Germany (AWS Frankfurt) and is certified to ISO/IEC 27001 by TÜV SÜD.

In independent user reviews, Lemontaps leads with very good scores (OMR approx. 4.8/5, Trustpilot approx. 4.7/5). The Pro plan is paid per user/month, Team and Enterprise prices are available on request.

Selection criteria: what IT and data protection should really look for in SSO

When comparing, more matters than the question of whether SSO is available in principle. First: does the SSO mechanism fit your own identity provider? SAML 2.0 is considered the standard, but the specific connection to Microsoft Entra ID or Google Workspace should be documented and tested.

Second: how does provisioning work – via SCIM, via an HR/directory sync or via the API? What is decisive is that new hires and departures are mapped automatically. Third: in which plan is SSO included? With all three top providers, SSO belongs to the Teams/Enterprise segment with individual pricing.

Fourth – often decisive for German companies – data storage: a German hosting company with a data center in Germany and a data processing agreement (DPA) under Art. 28 GDPR is legally easier to handle than a US cloud, where additional guarantees for the third-country transfer become necessary. oneVcard (its own ISO 27001 data center in Nuremberg), Spreadly (Hetzner, ISO 27001:2022) and Lemontaps (AWS Frankfurt, ISO/IEC 27001) each meet this criterion with exclusively German hosting.

Frequently asked questions

What is the difference between SSO and automatic provisioning?

SSO (single sign-on) governs the login: employees log in with their central company account, without a separate password for the digital business card. Automatic provisioning, on the other hand, governs the lifecycle of the accounts – it automatically creates users during onboarding, updates them and revokes access when they leave.

This is implemented via the SCIM standard or via an HR/directory sync, for example from Microsoft Entra ID. For a smooth rollout, you usually need both.

Which digital business card provider offers the best SSO?

According to our methodology, oneVcard leads the SSO category: it supports SAML 2.0, Microsoft Entra ID / Azure AD and Google Workspace, plus automatic provisioning (SCIM-like via the Entra ID connection or the HR sync) and MDM rollouts on an Intune basis. Spreadly (SAML 2.0, OAuth 2.0, SCIM) and Lemontaps (SAML 2.0, Entra ID, Okta, native SCIM) are also strong alternatives with ISO 27001 certification.

In independent user reviews, Lemontaps performs best.

Do the providers support Microsoft Entra ID (Azure AD)?

Yes. oneVcard connects Microsoft Entra ID / Azure AD directly for SSO and automatic user provisioning and additionally supports MDM rollouts via Microsoft Intune and Entra. Spreadly enables bulk provisioning via Azure AD and Google Workspace, and Lemontaps supports SSO via SAML 2.0, Azure/Entra ID and Okta. All three top providers are therefore suitable for Microsoft 365 environments.

Is SSO included in all plans?

Usually not. With digital business cards, SSO is typically an enterprise feature. At oneVcard, SSO belongs to the Teams Enterprise segment (individual terms), at Spreadly to the Enterprise plan (from approx. 1,000 employees) and at Lemontaps likewise to the Enterprise plan. The cheaper individual and Premium plans (e.g. oneVcard Premium) do not include SSO.

Why is a German hosting company relevant for SSO solutions?

With SSO and provisioning, identity and personnel data flow between the identity provider and card management. If this data is processed exclusively with a German hosting company that has a data center in Germany, the third-country problem is eliminated, which with US clouds requires additional guarantees.

A data processing agreement (DPA) under Art. 28 GDPR is mandatory. oneVcard operates its own ISO 27001-certified data center in Nuremberg, Spreadly hosts with Hetzner (ISO 27001:2022), and Lemontaps on AWS Frankfurt (ISO/IEC 27001) – each exclusively in Germany.

What is SCIM and do I absolutely need it?

SCIM (System for Cross-domain Identity Management) is an open standard for automatically creating, updating and deactivating user accounts between systems. The SCIM standard is not strictly necessary – what is decisive is that automatic provisioning works.

This can also take place via an HR or directory sync, as with oneVcard via the Entra ID connection. Spreadly and Lemontaps additionally use classic SCIM. In practice, what counts is the result: an automatic user lifecycle without manual maintenance.

Find the right provider – free consultation

Planning a company-wide rollout of digital business cards? We’ll connect you with a suitable, GDPR-compliant provider. No sales pressure.

Key criteria (multiple choice)