Setting up single sign-on for SAML and OIDC
Domain
company.com
.SAML Settings
The Ghost team will provide you with a unique SSO URL
and Entity ID
.
The SSO URL
will be in a format like https://app.ghostsecurity.ai/auth/saml/acs/<UUID>
. Depending on your platform, this may also be referred to as the Assertion Consumer Service URL or ACS URL
.
The Entity ID
will be in a format like https://app.ghostsecurity.ai/auth/saml/metadata/<UUID>
. Depending on your platform, this may also be referred to as the Audience URI
.
Enter these values when configuring your SAML application for Ghost.
Constraints
Next, set the Name ID
and Application username
values.
Set the Name ID
format to: EmailAddress
Set the Application username
to: Email
name
and role
attributes:
Name
name
attribute to user.firstName
.Role
role
attribute to user.ghost_role
.Metadata URL
https://<idp-provider>.com/app/yourappid/sso/saml/metadata
. Assign users