SAML 2.0 connects an identity provider that is not one of the named enterprise vendors. The form is the same SAML connection Okta, JumpCloud, and Ping Identity use. Users whose email domain matches the connection sign in at that IdP.
Open the connection
In the Authdog console:
- Select the project and environment.
- Open Authentication > Providers with the Enterprise filter.
- Choose SAML 2.0.
- Copy the service-provider values Authdog displays: SP-initiated sign-in URL, ACS / Reply URL, SP Entity ID, and the downloadable SP metadata XML.
- In the identity provider, create a SAML application and paste those values exactly.
Send the IdP's values back
| Field | Value |
|---|---|
| Connection name | A name that shows in the Configured list |
| IdP SSO URL | The IdP's SSO endpoint |
| IdP X.509 Certificate | The signing certificate, including the BEGIN and END lines |
Optional fields cover the IdP entity ID, sign-out URL, request signing (prefer RSA-SHA256 and SHA-256), and attribute names for email and name. Map attributes when the IdP does not send the email claim under the default name.
You can import IdP metadata from a URL or paste metadata XML. Import fills the SSO URL, certificate, entity ID, and logout URL when you select Fetch or Parse & autofill. It does not refresh itself later. Re-import when the IdP rotates the certificate.
Route by email domain
In Email domains (for SSO discovery), enter one or more domains separated by commas:
acme.com, eu.acme.comAn entry matches that domain and its subdomains. Only active enterprise connections participate. Do not overlap domains across connections. Resolution uses the first active match.
Test it
- Use the connection's Test action.
- Complete an SP-initiated sign-in.
- Confirm the assertion carries a stable subject and an email.
- Repeat in production with production URLs. A custom domain change can change the ACS URL. Update the IdP with the URL currently shown in the form.
Named vendors with the same form: Okta, JumpCloud, and Ping Identity.
Related
| Read | To learn how to |
|---|---|
| Enterprise SSO | SAML fields, domain routing, and certificate rotation |
| OpenID Connect | When the IdP speaks OIDC instead of SAML |
| Marketplace | The listing for this integration |