Skip to content

Single sign-on

ADFS

Connect Active Directory Federation Services (ADFS) to SurrealDB to allow members of your organisation to sign in with their Active Directory credentials. You add a relying party trust in ADFS Management, then enter your ADFS server's URL in a new connection in SurrealDB Studio.

Before you start, verify the email domain your company uses. You also need administrator access to your ADFS server.

The relying party trust takes two values from SurrealDB. Studio shows both in the Set up ADFS section of the connection form, with a copy button beside each.

ValueEnter in ADFS
Relying party trust identifierurn:auth0:auth0surrealdb
Endpoint URLhttps://auth.surrealdb.com/login/callback
  1. In ADFS Management, open Relying Party Trusts and select Add Relying Party Trust.

  2. Select Claims aware.

  3. Select Enter data about the relying party manually.

  4. Enter a display name, for example SurrealDB.

  5. Skip the token encryption certificate.

  6. Select Enable support for the WS-Federation Passive protocol, and enter the endpoint URL from the table above.

  7. Add the relying party trust identifier from the table above.

  8. Choose an access control policy, for example Permit everyone, and finish the wizard.

SurrealDB needs each person's email address and name.

  1. Select the new relying party trust, then Edit Claim Issuance Policy.

  2. Select Add Rule, then Send LDAP Attributes as Claims.

  3. Set Attribute store to Active Directory.

  4. Map the attributes:

LDAP attributeOutgoing claim type
E-Mail-AddressesE-Mail Address
Display-NameName
User-Principal-NameName ID
  1. Select Finish, then OK.

SurrealDB reads your server's configuration from its federation metadata endpoint, /FederationMetadata/2007-06/FederationMetadata.xml. Make sure this endpoint can be reached from the internet, for example by opening https://adfs.example.com/FederationMetadata/2007-06/FederationMetadata.xml from outside your network.

  1. Open Single sign-on in your enterprise and add a new connection.

  2. Select ADFS.

  3. Under Name the connection, enter a Display name. Members see this name on the sign-in screen.

  4. Under Enter the ADFS details, enter the ADFS server URL, for example https://adfs.example.com.

  5. Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.

  6. Select Create connection.

An ADFS connection has no client secret or certificate to enter. SurrealDB takes the signing certificate from the federation metadata.

If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.

Was this page helpful?