---
url: >-
  https://flip-chart.ru/developers/en/on-premise/installation/other/keycloak/saml.md
description: >-
  Set up sign-in to flip on-premise through Keycloak via SAML: create and
  configure the client, then get the IdP metadata and the verification
  certificate for flip.
---

# SAML integration with Keycloak

## Step 1. Creating a client

1. Go to **Clients**.

![Go to Clients](/on-premise/images/kk/kk-main-to-clients.png)

2. Click **Create client**

![Creating a client](/on-premise/images/kk/kk-clients-to-create.png)

3. Fill in the fields:

* **Client type** — select the **SAML** protocol;
* **Client ID** — enter the client identifier.

::: tip Note
The Client ID must contain the domain name on which the **flip** app runs.
:::

![Client creation, step 1](/on-premise/images/kk/kk-create-saml-step-1.png)

4. Specify **Valid redirect URIs** — the addresses to redirect to after authentication (multiple values are allowed).

::: tip Note
Valid redirect URIs must contain the domain name on which the **flip** app runs.
:::

![Client creation, step 2](/on-premise/images/kk/kk-create-saml-step-2.png)

***

## Step 2. Configuring the SAML client

![Client configuration, step 1](/on-premise/images/kk/kk-create-saml-setting-keys-0.png)

1. Go to the "Keys" tab

* Turn off request signing ("Client signature required") in the SAML client settings\
  ![Client configuration, step 2](/on-premise/images/kk/kk-create-saml-setting-keys-1.png)

2. Go to the SAML capabilities settings on the Settings tab

* Turn off "Force POST binding"
  ![Client configuration, step 3](/on-premise/images/kk/kk-create-saml-setting-keys-2.png)

3. Configuring the client scope

* Go to the "Client scopes" tab and select the client scope in use
  ![Client configuration, step 4](/on-premise/images/kk/kk-create-saml-client-scopes-0.png)
* Select "Add predefined mapper"
  ![Client configuration, step 5](/on-premise/images/kk/kk-create-saml-client-scopes-1.png)
* In the window that opens, select the mappers to use (X500 email, X500 givenName, X500 surname) and click "Add" to add them
  ![Client configuration, step 6](/on-premise/images/kk/kk-create-saml-client-scopes-2.png)
* Add one more mapper with the Add mapper → By configuration button
  ![Client configuration, step 7](/on-premise/images/kk/kk-create-saml-client-scopes-3.png)
* In the window that opens, select "User Attribute"
  ![Client configuration, step 8](/on-premise/images/kk/kk-create-saml-client-scopes-4.png)
* Set the Name, User Attribute, Friendly Name and SAML Attribute Name fields to "username".
* Set the SAML Attribute NameFormat field to Unspecified
  ![Client configuration, step 9](/on-premise/images/kk/kk-create-saml-client-scopes-5.png)

## Step 3. Getting the IdP metadata and the verification certificate

1. Go to **Realm settings**.

![Go to Realm settings](/on-premise/images/kk/kk-realm-setting.png)

2. Click the **SAML 2.0 Identity Provider Metadata** link. In the XML file that opens, find the following values:

* the contents of the verification certificate.
* save the page URL (this link is the "Identity provider metadata URL" that you enter when configuring SAML in flip).

![Viewing the metadata XML](/on-premise/images/kk/kk-realm-xml.png)

## Completing the setup

Enter the data you obtained as described in the [SSO](/en/on-premise/installation/other/sso) setup guide.
