Перейти до основного вмісту

Connect Keycloak with SAML

This guide explains how to add Casdoor to Keycloak as a SAML 2.0 identity provider (IdP).


Learning outcomes​

  • Import the Casdoor SAML metadata into Keycloak.
  • Configure the Casdoor application for Keycloak.
  • Sign in to Keycloak through Casdoor.

What you need​


Add the SAML IdP in Keycloak​

  1. In the Keycloak admin console, go to Identity providers and add a provider of type SAML v2.0.

    Identity providers in the Keycloak admin console

  2. Set Alias.

  3. Paste the SAML metadata URL of the Casdoor application into Import from URL and click Import. Keycloak fills in the SAML settings.

  4. Note the value of Service Provider Entity ID, and save the provider.

    SAML settings of the identity provider in Keycloak

For all options, see SAML v2.0 identity providers in the Keycloak documentation.

Configure the Casdoor application​

  1. In the Casdoor admin console, open the edit page of the application.

  2. Add the Service Provider Entity ID from Keycloak to Redirect URLs.

  3. Turn on Enable SAML compression. Keycloak requires compressed responses.

    Enable SAML compression switch

  4. Save the application.

Verify the result​

  1. Open the Keycloak sign-in page and click the button of the Casdoor provider.

    Keycloak sign-in page with the Casdoor provider

  2. Sign in on the Casdoor sign-in page. Casdoor sends you back to Keycloak, signed in.

    Keycloak after a successful sign-in

See also​