---
title: "Configuration"
manual: "Netresearch SAML Auth"
version: "main"
source: "Configuration/Index.rst"
rendered: "2026-10-01T05:49:07+00:00"
---

# Configuration {#configuration}

The extension is configured through a **SAML Auth Settings** record in the
TYPO3 backend.

-   [Configuration Reference](Reference.html#configuration-reference-1)

## Creating a Settings Record {#creating-a-settings-record}

1.  Go to **List** module on the root page (PID 0)
1.  Click **Create new record**
1.  Select **SAML Auth Settings**

## Service Provider (SP) Configuration {#service-provider-sp-configuration}

The Service Provider represents your TYPO3 installation.

### Entity ID {#entity-id}

The unique identifier for your Service Provider. Typically your domain URL:

```text
https://your-domain.tld
```

### Customer Service URL (ACS) {#customer-service-url-acs}

The Assertion Consumer Service URL where SAML responses are received:

```text
https://your-domain.tld/?logintype=login
```

### Name ID Format {#name-id-format}

The format for the Name ID in SAML assertions:

-   `urn:oasis:names:tc:SAML:2.0:nameid-format:transient` \- Temporary identifier
-   `urn:oasis:names:tc:SAML:2.0:nameid-format:emailAddress` \- Email address
-   `urn:oasis:names:tc:SAML:2.0:nameid-format:persistent` \- Persistent identifier

### Certificates {#certificates}

You can optionally configure SP certificates for signed requests:

-   **Certificate**: Public certificate (PEM format)
-   **Private Key**: Private key (PEM format)

## Identity Provider (IdP) Configuration {#identity-provider-idp-configuration}

The Identity Provider is your SSO server (e.g., Azure AD, Okta, SimpleSAMLphp).

### Entity ID {#entity-id-1}

The unique identifier provided by your IdP.

### SSO URL {#sso-url}

The Single Sign-On URL where authentication requests are sent.

### Logout URL {#logout-url}

The Single Logout URL for ending sessions (optional).

### Certificate {#certificate}

The IdP's public certificate for validating SAML responses (required).

## User Configuration {#user-configuration}

### Username Prefix {#username-prefix}

Optional prefix added to usernames created from SAML authentication:

```text
sso-
```

This helps identify SSO-created users in the system.

### User Folder {#user-folder}

Select the page (folder) where new frontend users will be stored.

### User Groups {#user-groups}

Select the default user groups assigned to newly created users.

## Auto-Discovery {#auto-discovery}

The extension supports automatic configuration discovery based on the request
domain. When a user attempts to login, the extension matches the current
domain against configured `sp_entity_id` values to find the appropriate
SAML configuration.

This allows multiple SAML configurations for different domains within the
same TYPO3 installation.
