We connect authentication in your application to a corporate SAML identity provider.
Larger organisations often require every business application to sign in through their central identity provider. It gives IT one place to enforce password rules and multi-factor authentication, and one place to remove access when someone leaves. SAML is the established standard for this in many enterprises.
What we build with it
- Enterprise single sign-on
- Centralised access control
- Attribute-based role assignment
How it works
- The organisation's identity provider and your application exchange metadata, including addresses and signing certificates.
- A user opens the application, or clicks its tile in the company portal, and is sent to the identity provider.
- After signing in there, the identity provider sends a signed SAML assertion back to the application.
- The application verifies the signature, reads the user's identity and group attributes, and signs them in with the matching role.
Data exchanged
- SAML assertions containing identity attributes
- Group or role attributes
What is needed to set it up
- A SAML identity provider
- Exchange of metadata between provider and application
- Attribute mapping to roles
Good to know
- Signing certificates expire. Renewals must be coordinated between the identity provider and the application, or sign-in stops working.
- SAML handles sign-in but not account removal. For automatic deprovisioning, a directory sync standard such as SCIM can be added.
- Accounts can be created on first sign-in from the assertion, so IT does not need to set up users twice.
