Prompt
Do I need both SAML and OIDC for B2B customers?
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
Not necessarily.
For B2B customers, whether you need SAML, OIDC, or both depends on who your customers are and what their identity providers support:
Rule of thumb
- Use OIDC if you want a simpler, modern integration and your customers can use it.
- Use SAML if you need compatibility with more enterprise customers, especially older corporate IdPs.
- Support both if you sell to a broad enterprise market and want to maximize customer compatibility.
Typical pattern for B2B
Many B2B SaaS products end up offering:
- OIDC for newer / cloud-native customers
- SAML for legacy enterprise customers
- Sometimes one of them is the default, with the other added only when required
When both make sense
You probably want both if:
- You sell to large enterprises
- Your customers use a mix of Azure AD / Entra, Okta, Ping, ADFS, OneLogin, etc.
- You want to reduce “we only support SAML” blockers in procurement or IT review
When one may be enough
You may only need OIDC if:
- Your customers are mostly modern SaaS companies
- You control the identity stack and can standardize on OIDC
- You want to minimize implementation and support complexity
You may only need SAML if:
- Your buyers are strongly enterprise/legacy-driven
- Their security teams explicitly require SAML
- Your product is already in a market where SAML is the expected norm
Practical recommendation
If you’re unsure, the safest approach for B2B is often:
- Start with OIDC if you want simpler implementation
- Add SAML if customer demand or enterprise deals require it
If you want, I can also give you a decision matrix for SAML vs OIDC based on your customer type, or a recommended default by IAM provider (Okta, Entra ID, Ping, etc.).