Skip to content

SAML integration with Keycloak ​

Step 1. Creating a client ​

  1. Go to Clients.

Go to Clients

  1. Click Create client

Creating a client

  1. Fill in the fields:
  • Client type — select the SAML protocol;
  • Client ID — enter the client identifier.

Note

The Client ID must contain the domain name on which the flip app runs.

Client creation, step 1

  1. Specify Valid redirect URIs — the addresses to redirect to after authentication (multiple values are allowed).

Note

Valid redirect URIs must contain the domain name on which the flip app runs.

Client creation, step 2


Step 2. Configuring the SAML client ​

Client configuration, step 1

  1. Go to the "Keys" tab
  • Turn off request signing ("Client signature required") in the SAML client settings
    Client configuration, step 2
  1. Go to the SAML capabilities settings on the Settings tab
  • Turn off "Force POST binding" Client configuration, step 3
  1. Configuring the client scope
  • Go to the "Client scopes" tab and select the client scope in use Client configuration, step 4
  • Select "Add predefined mapper" Client configuration, step 5
  • In the window that opens, select the mappers to use (X500 email, X500 givenName, X500 surname) and click "Add" to add them Client configuration, step 6
  • Add one more mapper with the Add mapper → By configuration button Client configuration, step 7
  • In the window that opens, select "User Attribute" Client configuration, step 8
  • Set the Name, User Attribute, Friendly Name and SAML Attribute Name fields to "username".
  • Set the SAML Attribute NameFormat field to Unspecified Client configuration, step 9

Step 3. Getting the IdP metadata and the verification certificate ​

  1. Go to Realm settings.

Go to Realm settings

  1. Click the SAML 2.0 Identity Provider Metadata link. In the XML file that opens, find the following values:
  • the contents of the verification certificate.
  • save the page URL (this link is the "Identity provider metadata URL" that you enter when configuring SAML in flip).

Viewing the metadata XML

Completing the setup ​

Enter the data you obtained as described in the SSO setup guide.

flip on-premise and cloud documentation