---
title: "Configuring SAML Authentication"
description: "Set up SAML 2.0 single sign-on in Talkspirit: enable the SAML provider, enter your identity provider's details, register Talkspirit with your IdP, map claims, enforce SSO, and troubleshoot sign-in."
category: administration-security
section: authentication-and-sso
tags: [admin]
type: Tutorial
lastUpdated: 2026-08-28
locale: en
canonical: https://support.talkspirit.com/en/administration-security/saml-authentication
---

# Configuring SAML Authentication


Talkspirit supports SAML 2.0 single sign-on (SSO), so members sign in through your organisation's identity provider (IdP) instead of a Talkspirit password. You configure it under **Administration → Authentication → SSO Providers**, where you enable the SAML provider, enter your identity provider's details, and register Talkspirit with your IdP. SAML SSO is available as an add-on to your subscription.

## How SAML sign-in works

Three parties take part in every SAML sign-in:

- **Your identity provider:** your company's own login system (Microsoft Entra ID, Okta, ADFS, OneLogin, Auth0, or any SAML 2.0 provider). Your IT team owns and operates it, not Talkspirit.
- **Keycloak:** an identity broker Talkspirit runs on your behalf. It speaks the SAML protocol with your identity provider so that Talkspirit's own application never handles SAML directly.
- **Talkspirit:** once the broker confirms who signed in, it hands Talkspirit a signed token, and the member is let in.

From a member's point of view, they click the **Log in with…** button (or land there automatically), authenticate on your usual company login page, and return to Talkspirit already signed in. Talkspirit never sees member passwords or your multi-factor policy: your identity provider handles authentication, and Talkspirit only receives a signed assertion confirming who signed in.

This gives you one less password per member, centralised access control (IT grants or revokes Talkspirit the same way it grants or revokes email), and the SSO many security policies and audits require.

## Before you begin

- You are an administrator of your Talkspirit organisation.
- Your organisation has the SAML SSO add-on. If the **SAML** card shows a **Locked** badge, contact Talkspirit to enable it.
- Your identity provider supports SAML 2.0. Supported presets include Okta, Microsoft, ADFS, OneLogin, and Auth0.

## How do I set up SAML authentication?

### Step 1: Enable SAML in Talkspirit

Go to **Administration → Authentication** and open the **SSO Providers** tab. Turn on the **SAML** toggle. The configuration form appears below the card.

![The SAML card on the SSO Providers tab, toggled on and expanded to show the configuration form: identity provider preset, Entity ID, SSO/SLO endpoint URLs, X.509 certificate, login button label, and NameID Format v2 switch](/images/administration-security/saml-authentication/01-saml-card-expanded.png)

### Step 2: Enter your identity provider's details

Fill in the form with the values from your identity provider:

| Field | What to enter |
| --- | --- |
| **Identity provider** | Your provider preset (Okta, Microsoft, ADFS, OneLogin, Auth0, Generic, or Custom), or **Not specified**. |
| **Entity ID (Issuer URL)** | Your identity provider's entity ID or issuer. Required. |
| **SSO Endpoint URL** | The URL members are redirected to when signing in. Required. |
| **SLO Endpoint URL** | The single logout URL. Optional. |
| **X.509 Certificate (PEM)** | Your provider's signing certificate, beginning with `-----BEGIN CERTIFICATE-----`. Required. |
| **Login button label** | Custom text for the sign-in button on your login page. Optional. |

To avoid retyping these values, select **Import IdP metadata**, then paste or upload the SAML 2.0 metadata document published by your identity provider. Talkspirit reads the endpoints and the signing certificate from it and fills the fields. Nothing is saved until you select **Save SAML configuration**.

> **The signing certificate matters most.** Talkspirit does not activate SAML sign-in until a valid certificate is saved: an entity ID and SSO URL alone are not enough. Without the certificate there is no way to verify that a sign-in response genuinely came from your identity provider, so Talkspirit will not stand up a partly configured, unverified connection. This is deliberate, not a bug.

#### Where to find these values in your identity provider

Every SAML 2.0 provider exposes the same values; only the labels and location differ. A few common ones:

| Identity provider | Where to find the values |
| --- | --- |
| **Microsoft Entra ID** (Azure AD) | Entra admin center → Enterprise Applications → your app → Single sign-on → SAML. "Azure AD Identifier" is the Entity ID, "Login URL" the SSO URL, "Logout URL" the SLO URL, and "Certificate (Base64)" the signing certificate. |
| **Okta** | Okta Admin Console → Applications → your app → Sign On → **View SAML setup instructions**. "Identity Provider Issuer" is the Entity ID, "Identity Provider Single Sign-On URL" the SSO URL, and the "X.509 Certificate" the signing certificate. |
| **Google Workspace** | Google Admin console → Apps → Web and mobile apps → your custom SAML app. It lists the SSO URL, Entity ID, and a downloadable certificate. |
| **ADFS, OneLogin, Auth0** | Each exposes an entity ID or issuer, an SSO URL, and a signing certificate somewhere in the app's configuration screen, even where the field names differ. |

Most providers let you download all of this as a single metadata file, which you can feed straight into **Import IdP metadata** above.

### Step 3: Register Talkspirit with your identity provider

Once you save, Talkspirit shows a **SAML 2.0 Service Provider Metadata** link. Open it and register that metadata URL with your identity provider so it can return assertions to Talkspirit. The metadata carries the Assertion Consumer Service (ACS) URL and the audience, so you do not copy those values separately. Some providers ask for this up front, when you first create the SAML app, before they show you their own values, so the exchange runs in both directions.

## How do I map identity provider claims?

When SAML is enabled, an **Attribute mappings** section appears below the provider cards. Use it to map claims from your identity provider onto Talkspirit member fields. Each mapping has three columns: **Identity provider claim**, **Keycloak field**, and **Talkspirit user field**. Add a mapping only when you need to carry a custom claim; standard fields such as email and name are handled by the default connection. Select **Save attribute mappings** to apply. Mappings run at every SAML and OpenID sign-in.

## How do I enforce SSO for all members?

To require SSO, open the **Sign-up settings** tab and turn off **Email and password**. Members can then sign in only through your active SSO providers. Talkspirit asks you to confirm, and it prevents you from disabling a sign-in method you are currently using, or the only method left, so you cannot lock yourself, or everyone, out. Enable another sign-in method before you disable email and password.

## How do I turn SAML off?

Disabling the **SAML** toggle on the **SSO Providers** tab turns SAML sign-in off for the whole organisation without deleting the configuration you entered. The effect is immediate: from the next sign-in attempt, members can no longer authenticate through your identity provider, even those mid-session, because each new request re-checks the toggle. This is the safe way to suspend SSO temporarily, for example during an incident on the identity-provider side, and re-enable it later without re-entering any values.

## Troubleshooting

Talkspirit does not host your company's login page, member passwords, or multi-factor policy: those are entirely your identity provider's responsibility. When a member cannot sign in with SSO, the cause is often on the identity-provider side (an expired certificate, a changed URL, a disabled directory account) rather than something visible inside Talkspirit.

| Symptom | First things to check |
| --- | --- |
| The **Log in with…** button does not appear at all | Is the SAML toggle still on? Is a valid certificate saved (not just the entity ID and SSO URL)? |
| Sign-in redirects to the identity provider but returns an error | Ask IT to confirm the certificate saved in Talkspirit still matches the current one on the identity provider. Certificates expire and get rotated. |
| One member cannot sign in, but everyone else can | Almost always an identity-provider-side issue. Check that member's status in your corporate directory first. |
| SSO stopped working for everyone at once | Check whether an admin recently turned the SAML toggle off, and whether the certificate is still valid. |
| Sign-in bounces back and forth without completing | Usually a mismatch between the ACS URL or entity ID your identity provider has on file and Talkspirit's current Service Provider Metadata. Ask IT to re-fetch it (Step 3). |

## What's next

- [Configuring Google Authentication](/en/administration-security/how-to-configure-google-authentication)
- [Automated user provisioning and de-provisioning (SCIM 2.0)](/en/administration-security/automated-user-provisioning-and-de-provisioning-scim-20)
- [Password Security Policy](/en/administration-security/password-security-policy)
