Personify IDP and SAML Client Integration Paige Freeman April 11, 2024 13:13 Updated Personify IDP version 6.0.0.4 supports SAML login and logout. As a SAML Identity Provider, client SAML Service Providers can integrate with Personify IDP. The following diagram depicts the SAML request/response flow. The SAML request/response flow requires configuration of the following components: Issuer: Personify IDP tenant configuration. The Issuer in this case is any of the Personify IDP tenants, e.g., https://login.personifytest.com/qastabletest SAML Client: Must be configured with Personify Web Admin, same as OIDC client SAML Service Provider: Must be configured with the Issuer and IDP SSO, SLO, Certificate, and other information SAML Client and Service Provider Configuration The SAML client must be configured within web admin. To configure the SAML client and service provider: Log in to web admin and select your org/environment. Navigate to Access Control > Manage Clients, then select Create New Client. Select a Protocol Type of SAML2P. Once you have selected the SAML2P protocol type, the SAML CONFIGURATION tab will be available to configure SSO and SLO URLs and other SAML provider settings. Continue to provide the general client information in the remaining fields as necessary.The SAML client creation is required in addition to the OIDC client configuration, which is done to provision IDP for a tenant. Select the SAML CONFIGURATION tab, then enter the SSO and SLO URLs and check the Sign Assertions checkbox. The ClientId of SAML client is EntityID. Select Review Client Settings and Save to save the client. After save, when you edit this client and navigate to the SAML CONFIGURATION tab, you will be able to see all the default claims that Personify IDP will return as part of a successful SAML login response. The claims can be identified within the Claim Mappings section, as shown below.