SAML single acs url for both IDP and SP initiated flow

131 views
Skip to first unread message

Karthik Narahari

unread,
Aug 10, 2022, 1:54:51 PM8/10/22
to Keycloak User
Hi everyone,
Can anyone help with process on how to configure both IDP and SP initiated flow when dealing with IDPs such as google.

For normal SAML based IDP configuration, we have 2 different urls supported 
1. <host>/auth/realms/<name>/broker/<name>/endpoint/clients/<clientName> for idp initiated flow where <clientName> is the saml client we redirect by default for all idp flows
2. <host>/auth/realms/<name>/broker/<name>/endpoint for sp initiated flow where we expect the redirection to automatically handle for any deep links to the apps after login.

Problem we see is with google, as it doesnt seem to be allowing multiple acs urls to be configured and hence we are not able to handle both flows together.
Is there a way we can handle both flows with single url ? 

-Karthik
Reply all
Reply to author
Forward
0 new messages