Zum Hauptinhalt springen
Veröffentlichung

SAML SSO for self-hosted instances

→ View the release details

SAML 2.0 single sign-on is now available for self-hosted Onetime Secret instances and custom domains running on v0.26.14. Your team can sign in through your organization's identity provider.

For self-hosted instances, connect an identity provider using three environment variables: SAML_IDP_SSO_SERVICE_URL, SAML_IDP_ENTITY_ID and SAML_IDP_CERT.

For custom domains, configure an identity provider in the domain's SSO settings. Each domain can use its own provider. The form displays the SP Entity ID, metadata URL and ACS URL you need to register with your provider.

Every SAML login includes checks to confirm that the response comes from the configured provider and matches a login request started by your instance. Responses can only be used once, and sign-ins must return to the registered address. User identities stay separate across providers, and each custom domain's identity provider settings are encrypted and tied to that domain.

See per-install-sso.md and per-domain-sso.md for setup instructions, provider registration details and troubleshooting codes.

SAML support for our EU, UK, CA, NZ and US hosted regional sites is coming soon.