Using Another Identity Provider (Open Source or Generic IdP) to Log in to Bob! Desk (SAML 2.0)
This document lists the information we need to enable SAML 2.0 SSO on your Bob! Desk account if your company uses an open source or generic identity provider (IdP) such as Keycloak, Authentik, Zitadel, Ory, WSO2 or ADFS, rather than Google, Microsoft Entra ID or Okta.
Bob! Desk relies on Supabase Auth for SAML 2.0 federation. Since the protocol is standardized, the configuration works the same way whatever your IdP, as long as it exposes a compliant SAML 2.0 endpoint.
1. Information to send us
The simplest option: the SAML metadata URL of your IdP (often called "metadata URL" or "federation metadata"). It stays up to date automatically when the IdP rotates its certificate.
If this URL is not publicly reachable (internal IdP), send us instead:
- The metadata XML file exported from your IdP
- Or, failing that, each of the following values:
- Your IdP's Entity ID / Issuer
- The SSO URL (authentication endpoint)
- The X.509 certificate (public signing key)
- The NameID format in use (
emailAddressorpersistent)
Please also tell us:
- The name of the attribute holding the email in the SAML assertion sent by your IdP (see section 3: some open source IdPs use non-standard attribute names)
- The email domain(s) of the users who will log in via SSO (e.g.
yourcompany.com) - The environment concerned: production or staging (see section 2)
2. Information we provide to you
Bob! Desk has a test environment (staging) separate from production. To validate the SSO connection before enabling it for your users, first configure a SAML application with the values from the "Staging" column, then a second one with the "Production" values when you are ready. The SSO connection is enabled independently on each environment.
To configure your SAML application on the IdP side, here is the Bob! Desk information:
| Item | Production | Staging (test) |
|---|---|---|
| Entity ID | https://general-api.bob-desk.com/auth/v1/sso/saml/metadata | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata |
| Metadata URL | https://general-api.bob-desk.com/auth/v1/sso/saml/metadata | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata |
| Metadata URL (download) | https://general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=true | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=true |
| ACS URL | https://general-api.bob-desk.com/auth/v1/sso/saml/acs | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/acs |
| SLO URL | https://general-api.bob-desk.com/auth/v1/sso/slo | https://staging-general-api.bob-desk.com/auth/v1/sso/slo |
| Start URL | https://app.bob-desk.com | https://staging.bob-desk.com |
Settings common to both environments:
| Setting | Value |
|---|---|
| NameID | emailAddress or persistent |
| Signed response | Required |
3. Attribute mapping to configure on your IdP
Configure your IdP so that it sends these attributes in the SAML assertion:
| Bob! Desk attribute | Must contain |
|---|---|
email | The user's email address |
user_name | The user's email address (same value as above) |
first_name | First name |
last_name | Last name |
Open source IdPs do not always expose the email attribute under the name "email" by default. Some use an eduPerson schema (e.g. urn:oid:0.9.2342.19200300.100.1.3) or a custom name defined by your administrator. Check the exact attribute name with your IT team, otherwise account synchronization fails silently.
4. Points of attention specific to open source IdPs
- HTTP-POST binding: make sure it is enabled for the SAML response. Some Keycloak or WSO2 deployments do not enable it by default on the Assertion Consumer Service.
- Signed response: the SAML response must be signed with the X.509 certificate you provide, so that we can verify its authenticity.
- Test environment: if possible, test first from a pre-production instance of your IdP, against our staging environment, rather than directly in production.
5. Finalization
Once your SAML application is configured on the IdP side, send us an email at tech@bob-desk.fr (click for a pre-filled email) containing:
- The metadata XML file (or its URL)
- The complete list of email domains concerned
- The name of the attribute holding the email, if different from "email"
- The environment concerned: production or staging
We will enable the SSO connection on the Bob! Desk side and confirm once the login test has been carried out. You will then be able to log in from https://app.bob-desk.com/sso-login (or https://staging.bob-desk.com/sso-login for the test environment) by entering your corporate email address.
