SAML

A SAML 2.0 identity provider you can self-host

Casdoor acts as a SAML 2.0 identity provider for your apps and SaaS tools, and as a SAML service provider when your customers or employees already have Entra ID, Okta or ADFS.

Casdoor as the IdP

Signed SAML responses, optional assertion signing, Single Logout and IdP-initiated SSO.

Attributes your apps need

Email, display name and name by default, plus custom attributes built from user fields, roles, permissions and groups.

Enterprise SSO for B2B

Give each customer an organization with its own SAML or OIDC identity provider, such as Okta, Entra ID or ADFS.

Provisioning too

Create and update users over SCIM 2.0, or sync them from Active Directory, Entra ID and Google Workspace.

What's included

  • SAML 2.0 IdP metadata per application
  • GET and POST SAML responses
  • Single Logout and IdP-initiated SSO
  • Guides for AWS, Google Workspace, Keycloak and Tencent Cloud
  • Upstream SAML: Entra ID, Google Workspace, Keycloak and custom IdPs
  • SCIM 2.0 provisioning API

Included in the free open-source edition and in every Casdoor Cloud plan.

SAML metadata
https://door.acme.com/api/saml/metadata?application=admin/app-acme

# Service providers read the SSO URL, issuer and signing
# certificate from this XML, so most need nothing else.

FAQ

Frequently asked questions

Where do I find Casdoor's SAML metadata?
Each application has its own metadata URL: <your Casdoor URL>/api/saml/metadata?application=admin/<application name>. Most service providers can import it directly.
Can Casdoor sign users in through another SAML identity provider?
Yes. Add Entra ID, Google Workspace, Keycloak, Alibaba Cloud or any other SAML IdP as a provider, and users sign in through it while your apps keep talking to Casdoor.