Use this guide if your SAML provider is not covered by a
specific integration guide. For PingIdentity, Entra ID, or
other providers with dedicated guides, refer to those instead.
Set up your identity provider (IdP)
Create a SAML 2.0 application in your identity provider.
- Log in to your identity provider’s admin console.
- Create a new SAML 2.0 application.
- Choose a name for the application (e.g. Honeydew).
-
In the SAML configuration, you will need to provide:
- ACS URL (Assertion Consumer Service URL)
- Entity ID (also called Audience URI or SP Entity ID)
https://example.com). These will be updated with the correct values in a later step. - Save the application configuration.
-
Locate and save the following information from your SAML application:
- Issuer ID (IdP Entity ID)
- Single Sign-On URL (SSO URL or SAML 2.0 Endpoint)
- Single Logout URL (SLO URL, if supported)
- X.509 Signing Certificate
-
Configure the following SAML attribute mappings:
- email - User’s email address (required)
- given_name - User’s first name (required)
- family_name - User’s last name (required)
- name - User’s full name (required)
- Assign users or groups that should have access to Honeydew.
Configure SAML support in Honeydew
Now that your SAML IdP is ready, configure it in Honeydew.Please pass the following information to your Honeydew contact or to [email protected]:
- Issuer ID (IdP Entity ID) from your SAML application
- Single Sign-On URL (SSO URL) from your SAML application
- Single Logout URL (if supported by your IdP)
- X.509 Signing Certificate from your SAML application
- Email domains used in your company’s email addresses
- Entity ID - The unique identifier for Honeydew (Service Provider)
- ACS URL - The Assertion Consumer Service URL for Honeydew
- Sign On URL - The URL to initiate single sign-on
Finish SAML configuration in your identity provider
- Return to your SAML application in your identity provider.
-
Edit the SAML configuration and update the placeholder values:
- Set Entity ID to the value provided by Honeydew
- Set ACS URL to the value provided by Honeydew
- Set Initiate Sign-On URL to the value provided by Honeydew (if your provider supports this field)
- Save your configuration.
- Enable the SAML application if it’s not already enabled.
- Notify your Honeydew contact or [email protected] that the configuration is complete.
- Once complete, test the SAML setup by logging in to Honeydew. Any user with an email address matching the domain you provided will be able to log in using your SAML provider. Upon login they will be redirected to your provider’s login page.
Required SAML Attributes
Your SAML provider must send the following attributes in the assertion:| Attribute | Description | Required |
|---|---|---|
email | User’s email address | Yes |
given_name | User’s first name | Yes |
family_name | User’s last name | Yes |
name | User’s full name | Yes |