Skip to main content

SAML

LoginLink supports SAML 2.0 as a service provider (SP), letting an enterprise tenant's own identity provider (Okta, OneLogin, Azure AD/Entra, ADFS, PingFederate, or any standards-compliant SAML IdP) authenticate its users directly.

Endpoints​

  • SP-initiated sign-in: GET /auth/Saml/start — redirects the user to your configured IdP's SSO endpoint.
  • Assertion Consumer Service (ACS): POST /auth/Saml/acs — where the IdP posts back the signed SAML assertion after the user authenticates.

Configuring a SAML connection​

Console → Connectors → SAML requires the standard SP/IdP metadata exchange:

  • Your IdP's SSO URL and signing certificate (or a metadata URL LoginLink can fetch both from automatically).
  • Attribute mapping — which SAML assertion attributes map to email, display name, and any custom fields.
  • LoginLink's own SP metadata (entity ID, ACS URL, signing certificate) to hand to your IdP administrator when setting up the connection on their side.

User provisioning​

Like the social/OAuth connectors, the first successful SAML assertion for a given identity creates the corresponding LoginLink user (just-in-time provisioning). If your organization provisions users ahead of time rather than on first sign-in, pair SAML for authentication with SCIM Provisioning for account lifecycle — this is the standard Okta/Azure AD pattern: SAML handles "who is this," SCIM handles "does this account exist and is it still active."