We connect authentication in your application to a corporate SAML identity provider.

Larger organisations often require every business application to sign in through their central identity provider. It gives IT one place to enforce password rules and multi-factor authentication, and one place to remove access when someone leaves. SAML is the established standard for this in many enterprises.

What we build with it

  • Enterprise single sign-on
  • Centralised access control
  • Attribute-based role assignment

How it works

  1. The organisation's identity provider and your application exchange metadata, including addresses and signing certificates.
  2. A user opens the application, or clicks its tile in the company portal, and is sent to the identity provider.
  3. After signing in there, the identity provider sends a signed SAML assertion back to the application.
  4. The application verifies the signature, reads the user's identity and group attributes, and signs them in with the matching role.

Data exchanged

  • SAML assertions containing identity attributes
  • Group or role attributes

What is needed to set it up

  • A SAML identity provider
  • Exchange of metadata between provider and application
  • Attribute mapping to roles

Good to know

  • Signing certificates expire. Renewals must be coordinated between the identity provider and the application, or sign-in stops working.
  • SAML handles sign-in but not account removal. For automatic deprovisioning, a directory sync standard such as SCIM can be added.
  • Accounts can be created on first sign-in from the assertion, so IT does not need to set up users twice.