CabsOn Service

Corporate Taxi SSO Login with Google and Microsoft 365

Single Sign-On for your CabsOn corporate account. Your staff sign in with their existing Google Workspace or Microsoft 365 credentials, and leavers are removed automatically.

Book Your Journey

Instant fixed-fare quotes for taxis and airport transfers across the UK.

CabsOn corporate SSO login lets your staff sign in to business.cabson.uk using their existing Google Workspace or Microsoft 365 accounts, with no separate CabsOn password to manage. We support OAuth 2.0 today and SAML 2.0 is on our near-term roadmap. New employees are auto-provisioned the first time they sign in, and anyone offboarded from your directory is automatically deprovisioned from CabsOn within twelve hours. For UK finance and travel teams, this means three concrete things. First, your existing MFA, conditional access, and device compliance policies continue to apply to every CabsOn ride booked by your team — we delegate authentication to your identity provider, so your rules are our rules. Second, leavers stop being a liability. When HR removes someone from your directory, they lose CabsOn access on the next sync cycle without a support ticket or a password reset. Third, your cost-centre allocations stay accurate because rides are booked under directory-verified identities mapped to Google Groups or Microsoft Entra groups, not against manually maintained lists that drift out of date. We are honest about what is not there yet. If you standardise on Okta, Ping, or a self-hosted ADFS via SAML, we are not the fastest option today — we are building SAML support and would welcome you into the pilot cohort. If you use Google Workspace or Microsoft 365 as your identity backbone (which covers most UK small and mid-sized businesses), you can be running SSO in about fifteen minutes and using it in production the same afternoon.
## How does CabsOn corporate SSO login actually work? Your staff go to business.cabson.uk and enter their work email address. Our login page detects the domain (for example @acme.co.uk), looks up the SSO configuration your admin has registered against that domain, and redirects the browser to Google or Microsoft. Your identity provider authenticates the user — running whatever MFA prompts, device checks, and conditional access rules you already have in place — and redirects back to us with a signed token. We verify the token, match it to a corporate user record, and drop the traveller straight into the booking flow. No CabsOn password is ever typed, stored, or reset. The whole exchange takes about two seconds. Behind the scenes we are using OAuth 2.0 and OpenID Connect. That is the same protocol family that Google Workspace and Microsoft 365 use to secure their own products, and it means your existing security investments — the MFA app your staff already have, the device trust rules you already publish — apply to CabsOn automatically. We do not run a parallel authentication stack, and we deliberately do not want to. Your directory should stay the system of record for who is and is not an employee. ## What identity providers does CabsOn support? Today: Google Workspace and Microsoft 365 (formerly Office 365) through OAuth 2.0 and OpenID Connect. These two providers cover the overwhelming majority of UK business identity stacks, from small independent hotels running Microsoft 365 Business Basic through to mid-market law firms on Google Workspace Enterprise. Not yet: SAML 2.0 assertions from Okta, Ping Identity, JumpCloud, self-hosted ADFS, or other pure SAML providers. We are building SAML 2.0 support and expect to ship it in a coming portal release. If your procurement mandates SAML today, please tell us during evaluation and we will let you know the current pilot timeline honestly. We would rather lose a deal on capability than win one and disappoint you at go-live. Also not yet: SCIM 2.0 push provisioning. Directory sync in CabsOn is pull-based — we ask your identity provider for the current state of your user list on a scheduled cycle, rather than accepting a push. Most customers cannot tell the difference. ## Does SSO change how we book rides? No — the booking experience is identical after login. Your staff still see the same Book A Ride screen, the same fleet options, the same fare estimates, the same UK-focused pickup coverage. What changes is who they are when they arrive at that screen. Because the login was directory-verified, we know which cost centre they belong to, which spending limit applies, and which manager needs to approve rides above that limit. All of that context flows into the booking without the traveller having to select it manually. For finance teams this is the quiet win. On a manual system you rely on the traveller to pick the right cost code every time, and any Monday-morning finance lead can tell you how well that works in practice. On SSO with directory-mapped cost centres, the ride is tagged correctly at source, and the monthly consolidated invoice comes out reconciled without a spreadsheet exercise. ## How does auto-provisioning work for new employees? The first time a new employee signs in via SSO, we create their CabsOn corporate user automatically. Admins control the rules from the SSO settings screen in the corporate portal: - **Domain allowlist** — restrict provisioning to specific email domains. Useful if you share a Microsoft tenant with a payroll bureau or an acquired subsidiary whose staff should not have CabsOn access. - **Directory group mapping** — link Google Groups or Microsoft Entra groups to CabsOn cost centres. A user in the acme-legal group is auto-created against the Legal cost centre; a user in acme-events lands in the Events cost centre. The rules are evaluated in priority order and the first match wins. - **Default spending limit** — set a per-ride cap that applies to newly provisioned users until a manager assigns something more specific. Common patterns are 30 pounds for staff and 60 pounds for named client-facing roles. - **Manual approval mode** — for stricter environments, hold every first login for admin review before the account is activated. Slower, but auditable. ## How does auto-deprovisioning work when someone leaves? Every twelve hours we compare our list of active corporate users against your Google Workspace or Microsoft 365 directory. Anyone who has been suspended, deleted, or moved into a leaver group in your directory is automatically disabled in CabsOn. That means: - They cannot log in through SSO. - They cannot log in through any other method (local passwords are disabled for SSO-managed domains). - They cannot be added as a passenger on a new booking. - Their historical booking data is retained for the VAT window required by HMRC and for your own reporting. An admin can also trigger an on-demand sync from the SSO settings screen. Most customers use this the moment HR confirms an exit, especially for higher-risk offboardings. Between scheduled sync and manual trigger, a leaver's window of residual access is typically minutes rather than days — a meaningful improvement over the industry norm of "we'll get to it in next month's access review". ## Is CabsOn corporate SSO GDPR compliant? Yes. We operate under UK GDPR and the Data Protection Act 2018 and take a minimum-necessary approach to identity data. Through SSO we ingest only the fields we need to bill and support the ride: display name, work email, employee ID where your directory provides one, and group membership for cost-centre mapping. We do not pull calendars, contacts, files, or any other data from your Google Workspace or Microsoft 365 tenant, and the OAuth consent screen shows precisely which scopes we ask for so your IT team can review them before installing. We publish a Data Processing Agreement for corporate customers, and we can complete standard vendor security questionnaires (including a filled Cyber Essentials-aligned response) on request from your procurement team. ## How does this compare to Uber for Business, Bolt Business, and Addison Lee? Honestly, on identity federation the field is more even than the marketing suggests. Uber for Business supports SSO with Google, Microsoft, Okta and SAML for enterprise customers — they are ahead of us on SAML today. Bolt Business currently focuses on email-plus-password with domain restrictions; SSO is a growing area but coverage varies by market. Addison Lee, as a specialist UK premium operator, has strong invoicing and traveller controls but their SSO story is enterprise-contract-led rather than self-service. Where we think CabsOn wins for UK small and mid-sized businesses is the combination: OAuth SSO you can turn on yourself in fifteen minutes, mapped to cost-centre and budget controls that reflect a UK VAT-compliant invoice you actually recognise. Where the giants are ahead is enterprise SAML federation and, in Uber's case, sheer market coverage outside the UK. If you are a UK company running Google Workspace or Microsoft 365 and you want directory-verified corporate travel without a six-month IT project, we are competitive. If you are a global 5,000-seat enterprise with a SAML-only identity policy, we would ask you to wait for our SAML release or trial us alongside an incumbent. ## What does SSO cost on a CabsOn corporate account? SSO is included on every corporate account at no extra charge. There is no per-seat identity fee, no premium tier that gates SSO behind a higher plan, and no minimum ride volume required to enable it. We took the view that identity federation is table stakes for a credible corporate travel product, not a paywall opportunity. The economics of managing password resets across a growing customer base are worse for us than the economics of properly delegated authentication, so this is genuinely a mutual win rather than a marketing line. You pay for rides. The corporate portal, cost-centre controls, monthly VAT invoicing, spend approvals, reporting, and SSO are all part of the account.
## Deeper technical detail on our SSO implementation We built SSO because our first ten corporate customers all asked the same question in the first onboarding call: "can our staff sign in with their work Google or Microsoft account?" Password reset requests were the single largest support ticket category on business accounts, and every one of them was a person whose IT team had already given them a perfectly good corporate identity. Making them invent a new CabsOn password was friction with no benefit. **How the OAuth handshake works today.** When your staff visit business.cabson.uk and enter their work email, our login page detects the domain (for example acme.co.uk), looks up the SSO configuration your admin has registered against that domain, and redirects the browser to Google or Microsoft. The identity provider authenticates the user against your own directory (including MFA, conditional access, device compliance and every other policy you already enforce), then redirects back to us with a signed token. We verify the token, match it to a corporate user record, and drop the traveller straight into the booking flow. The whole exchange happens in about two seconds and no password ever touches our servers. **Auto-provisioning rules you can tune.** In the corporate portal SSO settings screen you choose what happens the first time a new employee signs in. Options include: auto-create the user against a default cost centre, auto-create against a cost centre inferred from a Google Group or Microsoft Entra group, or require an admin to approve the first login. You can restrict SSO to specific domains (useful if you contract with a payroll bureau who share your Microsoft tenant), map job titles onto internal roles, and set a default per-ride spending limit that applies until a manager assigns something more specific. **Auto-deprovisioning through directory sync.** Every twelve hours we compare the list of active corporate users against your Google Workspace or Microsoft 365 directory. Anyone who has been offboarded, suspended, or moved to a leaver group is automatically disabled in CabsOn. Their booking history is preserved (we still need it for VAT), but they cannot log in and cannot be added as a passenger on a new booking. If you need faster propagation, an admin can trigger an on-demand sync from the SSO settings screen — most customers who use this feature run it manually the moment HR confirms an exit. **SAML 2.0 is on the roadmap.** OAuth 2.0 covers Google Workspace, Microsoft 365, and any provider that speaks OpenID Connect (which is most of them). A minority of larger enterprises standardise on SAML 2.0 via Okta, Ping, or a self-hosted ADFS. We are building SAML support for delivery in the next major portal release. If you have a SAML-only mandate and are evaluating us now, please tell us during onboarding and we will prioritise your metadata into the pilot cohort. **What we do not do.** We do not currently support SCIM 2.0 push provisioning. Sync is pull-based on our side. We do not federate directly with on-premise Active Directory — you would need Entra Connect or a similar bridge. And we do not resell identity: your directory of record stays with Google or Microsoft, and we hold only the minimum profile fields (name, email, employee ID, cost centre membership) required to bill the right department for the right ride.
Licensed drivers Greater Manchester or TfL Private Hire (PHV) licensing on every booking
DBS-checked Background-checked drivers with airport access permits
ULEZ & Clean Air ready Modern fleet meeting London ULEZ and Greater Manchester Clean Air Zone standards
Fixed fare guarantee Drop-off charge, congestion charge and ULEZ bundled into the quote, no surge pricing
Vehicle classes

What you can book for Manchester

Saloon

  • Up to 4 passengers
  • 2 standard suitcases
  • Most economical option

Default choice for solo travel, couples and pairs heading to the airport. Modern petrol-hybrid or fully electric saloons across the fleet.

Estate

  • Up to 4 passengers
  • 4 suitcases
  • Family-friendly

Choose this when bags outnumber people. A standard family of four with full check-in luggage fits cleanly in an estate where a saloon would not.

Executive

  • Mercedes E-Class or BMW 5 Series
  • Suited driver
  • Water and wifi included

Business class transport for corporate travellers, visiting clients and hotel transfers. The default for premium-postcode airport runs.

8-seater MPV

  • Up to 8 passengers
  • 8 suitcases capacity
  • Mercedes V-Class or Vito

Single-vehicle transport for groups of up to 8. Common on hen and stag bookings, sports teams, family airport runs and corporate group transfers.

Chauffeur

  • Mercedes S-Class or BMW 7 Series
  • Suited driver
  • VIP and wedding work

Flagship class for VIP travel, weddings, premium events and corporate visiting directors. Hourly hire from 4 hours minimum or fixed-route.

Every booking includes

What is in the fixed fare

Flight tracking on every airport pickup

Pickup time auto-adjusts to actual landing. No driver-side panic if your flight runs late.

60 minutes free waiting on arrivals

Plenty of buffer for immigration, baggage claim and customs at the busiest airport hours.

Drop-off charge included

The £5 forecourt fee at every UK airport is in the quote, not added at the kerb. Same with London congestion charge and ULEZ.

Optional meet and greet

Driver waits at the terminal arrivals exit with a name board. No extra charge.

Card, PayPal, corporate invoice

Pay how you want. Corporate accounts get monthly invoicing with PO numbers and VAT receipts.

Child and booster seats

Available on request, fitted before pickup. Confirm seat type at booking so we match the right vehicle.

Coverage

Manchester on the map

FAQs

Frequently asked questions

Does CabsOn support corporate SSO for taxi bookings?

Yes. We support Single Sign-On for corporate accounts through Google Workspace and Microsoft 365 using OAuth 2.0. Your staff sign in at business.cabson.uk with their existing work credentials — no separate CabsOn password to remember, reset, or leak. Setup takes about fifteen minutes for a corporate admin.

Which identity providers does CabsOn work with?

Today we support Google Workspace and Microsoft 365 (formerly Office 365) via OAuth 2.0 and OpenID Connect. This covers the majority of UK business identity stacks. SAML 2.0 support for Okta, Ping, ADFS and similar enterprise IdPs is on our near-term roadmap.

What happens when a new employee joins our company?

The first time they visit business.cabson.uk and sign in with their work Google or Microsoft account, we auto-provision a CabsOn corporate user against a default cost centre. Admins can restrict this to specific email domains, map directory groups to cost centres, or require manual approval before the first login is honoured.

What happens when an employee leaves the company?

We compare active corporate users to your directory every twelve hours. Any user who has been suspended, offboarded, or moved to a leaver group in Google Workspace or Microsoft 365 is automatically disabled in CabsOn. Their booking history is preserved for VAT, but they cannot log in or be added to new rides.

Do our staff still need a separate CabsOn password?

No. Once SSO is enabled for your domain, we disable password login for that domain by default. Your staff sign in through Google or Microsoft, inherit your MFA and conditional access policies, and never set a CabsOn-specific password. Local passwords remain available only for guest travellers you invite ad hoc.

Is CabsOn corporate SSO GDPR compliant?

Yes. We are UK GDPR compliant and hold only the minimum profile fields needed to bill and support the ride — name, work email, employee ID, and cost centre membership. Your identity provider remains the system of record. We publish a Data Processing Agreement for corporate customers on request.

How long does it take to set up SSO with CabsOn?

Most corporate admins finish SSO configuration in fifteen to thirty minutes. You register your domain in the SSO settings screen, authorise the CabsOn app inside your Google Workspace or Microsoft 365 admin console, pick provisioning rules, then test with one user. Rolling out to the wider team is usually a same-day activity.

Can we enforce Multi-Factor Authentication on CabsOn logins?

Yes — through your own identity provider. Because SSO delegates authentication to Google Workspace or Microsoft 365, whatever MFA, device compliance, IP restrictions, or conditional access policies you already enforce for those accounts apply to CabsOn logins automatically. We do not run a separate MFA stack.

What if only part of our organisation should be able to book taxis?

Restrict provisioning by directory group. During SSO setup you can tell us that only members of a specific Google Group or Microsoft Entra group (for example acme-travel-approved) may auto-provision. Everyone else is refused at the login screen, even if they hold a valid company email.

Does CabsOn support SAML 2.0 for enterprise identity providers?

Not yet — our current implementation is OAuth 2.0 and OpenID Connect, which covers Google Workspace and Microsoft 365 natively. SAML 2.0 support for Okta, Ping, and ADFS is in active development. If SAML is a hard requirement for your procurement, tell us during evaluation and we will prioritise you into the pilot cohort.

Can we still book rides for visitors or contractors who don't have SSO accounts?

Yes. Guest booking on behalf of a named traveller remains available to any authorised corporate user, regardless of how they signed in. You can book a ride for a job candidate, an out-of-town partner, or a contractor without giving them a CabsOn login of their own.

How does SSO change our monthly VAT invoice?

It doesn't change the invoice itself — you still receive one consolidated PDF on the 1st of each month with VAT itemised per ride. What SSO does change is accuracy: because every ride is booked under a directory-verified identity mapped to a cost centre, the department breakdown on your invoice reflects your real org chart, not manually maintained lists.