SAML providers
A SAML provider lets users sign in to Casdoor with an external SAML 2.0 identity provider (IdP), such as Keycloak, Azure AD, or Google Workspace. Casdoor is the service provider (SP). The IdP authenticates the user, and Casdoor never sees the credentials.
For the opposite direction, with Casdoor as the IdP of other applications, see Use Casdoor as a SAML identity provider.
Terms
| Term | Meaning |
|---|---|
| Identity provider (IdP) | The service that holds the identities and authenticates users, such as Keycloak or Azure AD |
| Service provider (SP) | The application that relies on the IdP. Here, Casdoor |
| Assertion Consumer Service (ACS) | The endpoint of the SP that receives the SAML assertions of the IdP |
How the sign-in works

Supported types
| Type | IdP |
|---|---|
Aliyun IDaaS | Alibaba Cloud IDaaS. See Alibaba Cloud IDaaS |
Keycloak | Keycloak. See Keycloak |
Custom | Any SAML 2.0 IdP. See Custom SAML, Azure AD, and Google Workspace |
| Alibaba Cloud IDaaS | Keycloak | Custom |
|---|---|---|
| ✅ | ✅ | ✅ |
Values for the IdP
When you register Casdoor at the IdP, use the following values. Replace <your-casdoor-domain> with the domain of Casdoor, for example door.example.com.
| Setting at the IdP | Value |
|---|---|
| ACS URL | https://<your-casdoor-domain>/api/acs |
| SP entity ID | The same URL: https://<your-casdoor-domain>/api/acs |
| Binding | HTTP POST. The /api/acs endpoint accepts only POST requests |
Usernames
Casdoor reads the user from the attributes of the SAML assertion, according to the attribute mapping of the provider. If the assertion has no username, Casdoor uses, in this order:
- The email address in the assertion
- The NameID of the assertion
Sign-in therefore works with IdPs that don't send a separate username attribute by default, such as Azure AD.
The SAML button on the sign-in page
Casdoor always shows a button for each SAML provider on the sign-in page, even if it is the only sign-in method. Unlike an OAuth provider, a SAML provider never redirects the user automatically. Users choose SAML explicitly, which avoids unexpected redirects where SAML is one option among several.