---
title: "Configuration Reference"
manual: "Netresearch SAML Auth"
version: "main"
source: "Configuration/Reference.rst"
rendered: "2026-10-01T05:49:07+00:00"
---

# Configuration Reference {#configuration-reference}

## SAML Settings Record Fields {#saml-settings-record-fields}

-   **name**

    -   *Type:* string
    -   *Required:* true

    A descriptive name for this SAML configuration.

-   **sp_entity_id**

    -   *Type:* string
    -   *Required:* true

    The unique identifier for your Service Provider (typically your domain URL).

-   **sp_customer_service_url**

    -   *Type:* string
    -   *Required:* true

    The Assertion Consumer Service URL where SAML responses are received.

-   **sp_customer_service_binding**

    -   *Type:* string
    -   *Default:* urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST

    The binding method for the ACS endpoint.

-   **sp_name_id_format**

    -   *Type:* string
    -   *Default:* urn:oasis:names:tc:SAML:2.0:nameid-format:transient

    The format for the Name ID in SAML assertions.

-   **sp_cert**

    -   *Type:* text

    The Service Provider's public certificate (PEM format).

-   **sp_key**

    -   *Type:* text

    The Service Provider's private key (PEM format).

-   **idp_entity_id**

    -   *Type:* string
    -   *Required:* true

    The unique identifier of the Identity Provider.

-   **idp_sso_url**

    -   *Type:* string
    -   *Required:* true

    The Single Sign-On URL of the Identity Provider.

-   **idp_sso_binding**

    -   *Type:* string
    -   *Default:* urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect

    The binding method for the SSO endpoint.

-   **idp_logout_url**

    -   *Type:* string

    The Single Logout URL of the Identity Provider.

-   **idp_cert**

    -   *Type:* text
    -   *Required:* true

    The Identity Provider's public certificate for validating responses.

-   **username_prefix**

    -   *Type:* string

    Optional prefix for usernames created via SAML authentication.

-   **users_pid**

    -   *Type:* int
    -   *Required:* true

    The page ID (folder) where new users will be created.

-   **usergroup**

    -   *Type:* string

    Comma-separated list of user group UIDs assigned to new users.

## Example Configuration {#example-configuration}

```text
# Service Provider Settings
Entity ID: https://your-domain.tld
Customer Service URL: https://your-domain.tld/?logintype=login
Customer Service Binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
Name ID Format: urn:oasis:names:tc:SAML:2.0:nameid-format:transient

# Identity Provider Settings
Entity ID: urn:example:idp
SSO URL: https://idp.example.com/sso
Binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
Certificate: [IDP Certificate]

# User Settings
Username Prefix: sso-
User Folder: [Select frontend user folder]
User Groups: [Select default frontend user groups]
```
