Using Another Identity Provider (Open Source or Generic IdP) to Log in to Bob! Desk (SAML 2.0)

This document lists the information we need to enable SAML 2.0 SSO on your Bob! Desk account if your company uses an open source or generic identity provider (IdP) such as Keycloak, Authentik, Zitadel, Ory, WSO2 or ADFS, rather than Google, Microsoft Entra ID or Okta.

Bob! Desk relies on Supabase Auth for SAML 2.0 federation. Since the protocol is standardized, the configuration works the same way whatever your IdP, as long as it exposes a compliant SAML 2.0 endpoint.

1. Information to send us

If this URL is not publicly reachable (internal IdP), send us instead:

  • The metadata XML file exported from your IdP
  • Or, failing that, each of the following values:
    • Your IdP's Entity ID / Issuer
    • The SSO URL (authentication endpoint)
    • The X.509 certificate (public signing key)
    • The NameID format in use (emailAddress or persistent)

Please also tell us:

  • The name of the attribute holding the email in the SAML assertion sent by your IdP (see section 3: some open source IdPs use non-standard attribute names)
  • The email domain(s) of the users who will log in via SSO (e.g. yourcompany.com)
  • The environment concerned: production or staging (see section 2)

2. Information we provide to you

Bob! Desk has a test environment (staging) separate from production. To validate the SSO connection before enabling it for your users, first configure a SAML application with the values from the "Staging" column, then a second one with the "Production" values when you are ready. The SSO connection is enabled independently on each environment.

To configure your SAML application on the IdP side, here is the Bob! Desk information:

ItemProductionStaging (test)
Entity IDhttps://general-api.bob-desk.com/auth/v1/sso/saml/metadatahttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata
Metadata URLhttps://general-api.bob-desk.com/auth/v1/sso/saml/metadatahttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata
Metadata URL (download)https://general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=truehttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=true
ACS URLhttps://general-api.bob-desk.com/auth/v1/sso/saml/acshttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/acs
SLO URLhttps://general-api.bob-desk.com/auth/v1/sso/slohttps://staging-general-api.bob-desk.com/auth/v1/sso/slo
Start URLhttps://app.bob-desk.comhttps://staging.bob-desk.com

Settings common to both environments:

SettingValue
NameIDemailAddress or persistent
Signed responseRequired

3. Attribute mapping to configure on your IdP

Configure your IdP so that it sends these attributes in the SAML assertion:

Bob! Desk attributeMust contain
emailThe user's email address
user_nameThe user's email address (same value as above)
first_nameFirst name
last_nameLast name

4. Points of attention specific to open source IdPs

  • HTTP-POST binding: make sure it is enabled for the SAML response. Some Keycloak or WSO2 deployments do not enable it by default on the Assertion Consumer Service.
  • Signed response: the SAML response must be signed with the X.509 certificate you provide, so that we can verify its authenticity.
  • Test environment: if possible, test first from a pre-production instance of your IdP, against our staging environment, rather than directly in production.

5. Finalization

Once your SAML application is configured on the IdP side, send us an email at tech@bob-desk.fr (click for a pre-filled email) containing:

  • The metadata XML file (or its URL)
  • The complete list of email domains concerned
  • The name of the attribute holding the email, if different from "email"
  • The environment concerned: production or staging

We will enable the SSO connection on the Bob! Desk side and confirm once the login test has been carried out. You will then be able to log in from https://app.bob-desk.com/sso-login (or https://staging.bob-desk.com/sso-login for the test environment) by entering your corporate email address.