Connect SAML

Learn how to configure a new Generic SAML SSO Connection

Introduction

Each SSO Identity Provider requires specific information to create and configure a new Connection. Often, the information required to create a Connection will differ by Identity Provider.

To create a Generic SAML Connection, you'll need the Identity Provider Metadata URL that is available from your Enterprise customer's SAML instance.

WorkOS Provides

WorkOS provides the ACS URL and the SP Metadata link. They are readily available in your Connection's Settings in the WorkOS Dashboard.

The ACS URL is the location an Identity Provider redirects its authentication response to. The SP Metadata link contains a metadata file that your Enterprise customer can use to set up the SAML integration.

Overview

And then, you provide the IdP Metadata URL.

Normally, this information will come from your Enterprise customer's IT Management team when they set up your application's SAML 2.0 configuration in their Identity Provider admin dashboard. But, should that not be the case during your setup, here's how to obtain them.

1

Enter Service Provider Details

Copy and Paste the "ACS URL" into the corresponding fields for Service Provider details and configuration. For some SAML setups, you can use the metadata found at the SP Metadata link to configure the SAML connection.

2

Obtain Identity Provider Metadata

Copy the IdP Metadata URL from your SAML settings and upload it to your WorkOS Connection settings. Your Connection will then be linked and good to go!

NOTE: Some Generic SAML providers might not be able to provide the IdP Metadata URL. In these cases, you'll want to manually configure the connection.