Configure SAML with Authentik

This page explains how to integrate Authentik as a SAML Identity Provider to authenticate your users on Reemo.

Note

Depending on your deployment mode, SSO can be enabled at the instance level (Private Cloud / On-Prem) or at the organization level (Public Cloud).
Screenshots and labels may vary slightly depending on your interface version.

Configure SSO in Reemo

Case 1: Instance level (Private Cloud / On-Prem)
From verified_user Admin Area > dashboard General > passkey SSO Connectors, configure SSO for the instance.
Access SSO Connectors in the instance Admin Area

Access SSO Connectors in the instance Admin Area.

Case 2: Organization level (Public Cloud)
From domain Organization > dashboard General > passkey SSO Connectors, configure SSO for that organization.
Configure SSO in Organization > SSO Connectors

Configure SSO in Organization > SSO Connectors.

Create the SAML connector in Reemo

  1. From verified_user Admin Area > domain Organizations, select your organization, then go to dashboard General > passkey SSO Connectors and click New Connector > New SAML Connector.

  2. Fill in the basic fields:

    • Friendly Name: name displayed to your users (e.g. Authentik).

    • Issuer / App URI ID: reemo.

    • Entry Point: will be filled in after the Authentik configuration.

    • IdP Logout URL and Logout protocol (optional): see the Configure Logout at the Identity Provider section below.

    • Certificate: will be filled in after the Authentik configuration.

    • Attributes Mapping: attribute names Reemo expects in the SAML assertion (email, username, fullname by default) — you will reuse these exact names in the Property Mappings you create in Authentik.

  3. Click Create to generate the connector’s callback URL. You will need it in Authentik.

Retrieving the connector callback URL

Copy the callback URL generated by the SAML connector.

Configure the SAML application in Authentik

Log in to the Authentik admin interface (https://[authentik_url]/if/admin/).

1. Create the attribute mappings (Property Mappings)

Reemo reads, from the assertion, the attributes defined in the connector’s Attributes Mapping (email, username and fullname by default). Authentik does not expose these short names by default: you must create three dedicated Property Mappings.

In the Customization > Property Mappings menu, click Create > SAML Provider Property Mapping, then create the following three mappings:

Name

SAML Attribute Name

Expression

reemo email

email

return request.user.email

reemo username

username

return request.user.username

reemo fullname

fullname

return request.user.name

Warning

The SAML Attribute Name field must match the connector’s attribute names in Reemo exactly (email, username, fullname). Without this match, attributes arrive under a different name in the assertion and Reemo ignores them.

Creating a SAML Property Mapping in Authentik

Set the SAML Attribute Name and the mapping expression.

List of the reemo Property Mappings

The three email, username and fullname mappings once created.

2. Create the application and the SAML provider

In the Applications > Applications menu, click Create with Wizard.

Create an application in Authentik

Start the application creation wizard.

Follow the wizard:

  • Application: Name = reemo, Slug = reemo.

  • Provider Type: SAML Provider.

  • Protocol settings:

    • ACS URL: paste the callback URL from the Reemo connector.

    • Audience: reemo (same value as the connector’s Issuer / App URI ID in Reemo).

  • Advanced protocol settings:

    • Signing Certificate: select a certificate (e.g. authentik Self-signed Certificate).

    • Sign assertions: ON.

    • Sign responses: ON.

    • Verification Certificate: leave empty.

    • Property Mappings: select reemo email, reemo username and reemo fullname.

    • NameID Property Mapping: authentik default SAML Mapping: Email.

    • Service Provider Binding: Post.

Warning

Leave the Verification Certificate field empty. Reemo does not sign its outgoing SAML requests; if a verification certificate is set, Authentik will reject the authentication requests.

Authentik SAML provider configuration

Signing certificate, Sign assertions/responses, Property Mappings and NameID of the provider.

3. Retrieve the certificate and the Entry Point

Open the provider (Applications > Providers > reemo). The Overview tab provides everything Reemo needs:

  • Certificate: Download signing certificate button (or System > Certificates). Open the file and copy the raw base64 content.

  • Entry Point: the SAML Endpoint field, in the format:

    https://[authentik_url]/application/saml/[slug]/
    

Warning

Paste only the raw base64 of the signing certificate, otherwise Reemo will not be able to validate the signed assertions.

Authentik SAML provider overview

Retrieve the signing certificate, the SAML Endpoint and the ACS URL.

Complete the Reemo SAML connector with this information (Entry Point and Certificate). Enable the connector (check Enabled) then click Update to save.

Declare users

Two approaches are available to grant SSO access to users.

Approach A: Explicit provisioning from the organization
From verified_user Admin Area > domain Organizations, select your organization, then go to inventory_2 Inventory > person Users and click New User > Provision SAML User to add users by entering their email.
New User menu with the Provision SAML User option

Select Provision SAML User from the New User menu.

SAML user add popup by email

Add users by email via the provisioning popup.

Approach B: Just-In-Time (JIT) Provisioning
From verified_user Admin Area > domain Organizations, select your organization, then go to dashboard General > passkey SSO Connectors, click the connector then enable Just In Time Provisioning: accounts are created automatically on the first successful SSO login.
Just In Time Provisioning option

Enable Just In Time Provisioning to create accounts on first login.

Manage rights dynamically from the directory

This configuration lets Reemo read each user’s group membership from your corporate directory and automatically assign access to the corresponding collections — without manually provisioning rights in Reemo.

In Authentik

  1. Create a dedicated SAML Property Mapping (Customization > Property Mappings > Create > SAML Provider Property Mapping):

    • Name: reemo groups

    • SAML Attribute Name: groups

    • Expression:

      for group in request.user.groups.all():
          yield group.name
      
  2. Add this reemo groups mapping to the Property Mappings of the reemo provider (Advanced protocol settings).

  3. Create your groups under Directory > Groups and add users to them. The group name is the value sent in the groups attribute.

Warning

Do not use the managed authentik default SAML Mapping: Groups mapping: it emits the attribute under the name http://schemas.xmlsoap.org/claims/Group, which Reemo does not recognize via the short name groups. Use the custom mapping above.

In Reemo

  1. Open the SSO connector form by going to Admin Area > General > SSO Connectors.

  2. In the connector settings, open the Extra mapping section.

  3. In the Collection field, enter the group attribute name configured in Authentik (e.g. groups), then click Update.

Extra Mapping section in the Reemo SSO connector

Enter the group attribute name in the Collection field of Extra Mapping.

  1. In Inventory > Collections, select a collection and click Edit. In the SSO Mapping Identifier field, enter the corresponding group name from your directory.

When a user logs in via SAML, Reemo reads the groups sent by Authentik and applies collection rights automatically.

Configure Logout at the Identity Provider

The SAML connector exposes two additional fields to automatically log the user out of their identity provider (IdP) when they log out of Reemo: an IdP Logout URL and a Logout protocol.

  • Redirect to the URL above (default): the browser is simply redirected to the configured URL. Works with any provider exposing a logout endpoint that responds to a plain GET request, with no extra configuration on its side.

  • SAML single logout (signed LogoutRequest): Reemo signs an actual LogoutRequest built from the session subject, and handles both the LogoutResponse returned by the provider and any LogoutRequest it initiates on its own. This is the only mode that works with a provider whose logout endpoint is the same as its login endpoint (e.g. Microsoft Entra ID, Keycloak): that endpoint expects a signed SAML request, not a plain GET.

Note

Both fields are optional and backward-compatible: the protocol defaults to Redirect to the URL above, so existing connectors keep their current behavior. The login strategy is never affected, and a logout failure on the provider’s side never blocks the user’s logout from Reemo.

SAML single logout requires a service provider key to exist for this connector: without it, the connector automatically falls back to Redirect to the URL above. Reemo generates this key pair per connector — the private key never leaves the server — and the corresponding certificate, to declare on the provider’s side, is displayed in the SSO connector list.

Warning

SAML single logout requires two declarations on the identity provider’s side: a logout callback URL pointing to Reemo (its format depends on the provider — see the corresponding guide) and the connector’s signing certificate, displayed in the SSO connector list. Without both, the provider rejects the LogoutRequest signed by Reemo.

Warning

In SAML single logout mode, set the IdP Logout URL based on your provider:

  • Leave it empty if your provider serves logout on its login endpoint (e.g. Microsoft Entra ID, Keycloak). Reemo then reuses the Entry Point already configured.

  • Fill it in if your provider exposes a separate logout endpoint (e.g. Okta).

Warning

Logging out on the identity provider’s side closes the browser session for the whole provider, not just Reemo. A user with other tabs open on the same provider (e.g. other Microsoft services) is logged out of those too.

Log in via SAML

Once the connector is active and users are declared (or JIT is enabled), your users can log in:

  • General access to your portal (Private Cloud / On-Prem):

    https://[portal_url]/
    
  • Direct access to the organization (Public Cloud):

    https://[portal_url]/login/[organization_shortname]
    

On the login screen, select the SSO tab, then click Login to be redirected to the identity provider.

SSO tab on the login screen

Select the SSO tab, then click Login.