Authdog
Log In

Enterprise Connections · Setup

Set up SAML 2.0

SAML 2.0 connects an identity provider that is not one of the named enterprise vendors.

The form is the same SAML connection Okta, JumpCloud, and Ping Identity use. Users whose email domain matches the connection sign in at that IdP.

Open the connection

In the Authdog console:

  1. Select the project and environment.
  2. Open Authentication > Providers with the Enterprise filter.
  3. Choose SAML 2.0.
  4. Copy the service-provider values Authdog displays: SP-initiated sign-in URL, ACS / Reply URL, SP Entity ID, and the downloadable SP metadata XML.
  5. In the identity provider, create a SAML application and paste those values exactly.

Send the IdP's values back

Field Value
Connection name A name that shows in the Configured list
IdP SSO URL The IdP's SSO endpoint
IdP X.509 Certificate The signing certificate, including the BEGIN and END lines

Optional fields cover the IdP entity ID, sign-out URL, request signing (prefer RSA-SHA256 and SHA-256), and attribute names for email and name. Map attributes when the IdP does not send the email claim under the default name.

You can import IdP metadata from a URL or paste metadata XML. Import fills the SSO URL, certificate, entity ID, and logout URL when you select Fetch or Parse & autofill. It does not refresh itself later. Re-import when the IdP rotates the certificate.

Route by email domain

In Email domains (for SSO discovery), enter one or more domains separated by commas:

acme.com, eu.acme.com

An entry matches that domain and its subdomains. Only active enterprise connections participate. Do not overlap domains across connections. Resolution uses the first active match.

Test it

  1. Use the connection's Test action.
  2. Complete an SP-initiated sign-in.
  3. Confirm the assertion carries a stable subject and an email.
  4. Repeat in production with production URLs. A custom domain change can change the ACS URL. Update the IdP with the URL currently shown in the form.

Named vendors with the same form: Okta, JumpCloud, and Ping Identity.

Read To learn how to
Enterprise SSO SAML fields, domain routing, and certificate rotation
OpenID Connect When the IdP speaks OIDC instead of SAML
Marketplace The listing for this integration