Skip to content

Single sign-on

Keycloak

Connect Keycloak to SurrealDB to allow members of your organisation to sign in with the accounts in a Keycloak realm. The connection uses SAML. You create a SAML client in your realm, add a connection in SurrealDB Studio, and then finish the client with values from Studio.

Before you start, verify the email domain your company uses. You also need administrator access to the Keycloak realm.

The Keycloak client ID must be the connection's entity ID, which includes the connection's name. That name exists only after you create the connection, so the setup finishes in Keycloak.

  1. In the Keycloak admin console, select your realm.

  2. Open Realm settings, then Keys, and copy the Certificate of the RS256 key.

  3. Note the realm's SAML endpoint, which has the form https://keycloak.example.com/realms/<realm>/protocol/saml.

The certificate in Keycloak has no header or footer. Add -----BEGIN CERTIFICATE----- on the line before it and -----END CERTIFICATE----- on the line after it to make it PEM-encoded.

  1. Open Single sign-on in your enterprise and add a new connection.

  2. Select Keycloak.

  3. Under Name the connection, enter a Display name. Members see this name on the sign-in screen.

  4. Under Enter the Keycloak details, enter:

    • Sign-in URL: the realm's SAML endpoint from step 1.

    • Sign-out URL: optional. The realm's SAML endpoint also handles sign-out, so you can enter the same URL.

    • X.509 signing certificate: the PEM-encoded certificate from step 1.

  5. Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.

  6. Select Create connection.

Studio opens the Sign-on tab of the new connection.

The Set up Keycloak section of the Sign-on tab shows the values for the client, with a copy button beside each. <connection> is the connection's name.

ValueForm
Entity IDurn:auth0:auth0surrealdb:<connection>
Assertion Consumer Service (ACS) URLhttps://auth.surrealdb.com/login/callback?connection=<connection>
  1. In your realm, open Clients and select Create client.

  2. Set Client type to SAML.

  3. Set Client ID to the entity ID.

  4. Add the ACS URL under Valid redirect URIs.

  5. Save the client.

  6. Under Client scopes, map each person's email address to the NameID or to an email attribute. Setting Name ID format to email on the client's settings does this for the NameID.

If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.

Was this page helpful?