Ana içeriğe geç

SAML providers

A SAML provider lets users sign in to Casdoor with an external SAML 2.0 identity provider (IdP), such as Keycloak, Azure AD, or Google Workspace. Casdoor is the service provider (SP). The IdP authenticates the user, and Casdoor never sees the credentials.

For the opposite direction, with Casdoor as the IdP of other applications, see Use Casdoor as a SAML identity provider.

Terms​

TermMeaning
Identity provider (IdP)The service that holds the identities and authenticates users, such as Keycloak or Azure AD
Service provider (SP)The application that relies on the IdP. Here, Casdoor
Assertion Consumer Service (ACS)The endpoint of the SP that receives the SAML assertions of the IdP

How the sign-in works​

SAML sign-in between the user, Casdoor, and the IdP

Supported types​

TypeIdP
Aliyun IDaaSAlibaba Cloud IDaaS. See Alibaba Cloud IDaaS
KeycloakKeycloak. See Keycloak
CustomAny SAML 2.0 IdP. See Custom SAML, Azure AD, and Google Workspace
Alibaba Cloud IDaaSKeycloakCustom
✅✅✅

Values for the IdP​

When you register Casdoor at the IdP, use the following values. Replace <your-casdoor-domain> with the domain of Casdoor, for example door.example.com.

Setting at the IdPValue
ACS URLhttps://<your-casdoor-domain>/api/acs
SP entity IDThe same URL: https://<your-casdoor-domain>/api/acs
BindingHTTP POST. The /api/acs endpoint accepts only POST requests

Usernames​

Casdoor reads the user from the attributes of the SAML assertion, according to the attribute mapping of the provider. If the assertion has no username, Casdoor uses, in this order:

  1. The email address in the assertion
  2. The NameID of the assertion

Sign-in therefore works with IdPs that don't send a separate username attribute by default, such as Azure AD.

The SAML button on the sign-in page​

Casdoor always shows a button for each SAML provider on the sign-in page, even if it is the only sign-in method. Unlike an OAuth provider, a SAML provider never redirects the user automatically. Users choose SAML explicitly, which avoids unexpected redirects where SAML is one option among several.

See also​