Skip to content

Single sign-on

SAML

Connect any identity provider that supports SAML 2.0 to SurrealDB. Use this connection when your provider is not listed by name. You create a SAML application in your identity provider, add a connection in SurrealDB Studio, and then finish the application with values from the connection.

Before you start, verify the email domain your company uses.

A SAML connection is set up in this order because the values your identity provider needs from SurrealDB include the connection's name, which exists only after you create the connection.

  1. In your identity provider, create a SAML 2.0 application.

  2. Send each person's email address as the NameID, or as an email attribute.

  3. Copy the provider's single sign-on URL and its X.509 signing certificate.

Some providers ask for an ACS URL and an entity ID before they save the application. If yours does, enter a temporary value such as https://auth.surrealdb.com/login/callback and replace it in step 3.

  1. Open Single sign-on in your enterprise and add a new connection.

  2. Select SAML.

  3. Under Name the connection, enter a Display name. Members see this name on the sign-in screen.

  4. Under Enter the SAML details, enter:

    • Sign-in URL: the provider's single sign-on URL, for example https://idp.example.com/sso/saml.

    • Sign-out URL: optional. The provider's single logout URL.

    • X.509 signing certificate: the PEM-encoded certificate, starting with -----BEGIN CERTIFICATE-----.

  5. Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.

  6. Select Create connection.

Studio opens the Sign-on tab of the new connection.

The Set up SAML section of the Sign-on tab shows three values, with a copy button beside each. <connection> is the connection's name, which is also shown on the General tab.

ValueAlso calledForm
Assertion Consumer Service (ACS) URLReply URL, single sign-on URLhttps://auth.surrealdb.com/login/callback?connection=<connection>
Entity IDAudience, SP entity IDurn:auth0:auth0surrealdb:<connection>
Metadata URLhttps://auth.surrealdb.com/samlp/metadata?connection=<connection>

Enter the ACS URL and the entity ID in the SAML application. If your provider can import service provider metadata, give it the metadata URL instead, which contains both.

Copy the values from Studio rather than building them by hand, so the connection name is exact.

If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.

Was this page helpful?