Generic SAML 2.0 provider
Myra AI Workspace signs users in through any SAML 2.0 identity provider (IdP) — Okta, Auth0, Keycloak, ADFS, and enterprise directories. Myra acts as the SAML service provider (SP). For Microsoft Entra ID, follow the dedicated Microsoft Entra ID guide.
Single sign-on authenticates existing accounts only — provision the users first. Required role:
tenant admin or admin (the SSO_MANAGE permission).
Note: The examples use the production admin-API host
ai-api-admin.myra.eu. On the integration environment, substituteai-api-admin-int.myra.eu.
Reading the SP values from Myra
- Open Administration → Tenants → the tenant → edit dialog → Single sign-on (SSO).
- Select the SAML 2.0 SSO checkbox. -> The panel displays the SP metadata URL and the ACS URL to register at the identity provider. The Logout (SLS) URL follows the same pattern and appears in the served metadata when a Single Logout URL is set.
The SP URLs follow this pattern, where <tenant-id> is the Myra tenant UUID (the id from the
tenant list, not the slug):
| IdP field | Myra SP value |
|---|---|
| Entity ID / Identifier | https://ai-api-admin.myra.eu/admin/auth/saml/<tenant-id>/metadata |
| Assertion Consumer Service (ACS) / Reply URL | https://ai-api-admin.myra.eu/admin/auth/saml/<tenant-id>/acs |
| Single Logout Service (SLS) / Logout URL | https://ai-api-admin.myra.eu/admin/auth/saml/<tenant-id>/sls |
These URLs are served on the admin-API host over HTTPS, not on the application host ai.myra.eu. The
SP metadata document at the metadata URL is authoritative.
Note: Register the values exactly as the Myra panel and the SP metadata show them. A host or scheme mismatch causes the identity provider to reject the assertion.
Registering the SP at the identity provider
- Create a new SAML application at the identity provider.
- Enter the Myra Entity ID, ACS URL, and Logout URL from the table above.
- Set the NameID (the unique user identifier) to a stable value — the user's email address or a
persistent object identifier.
- Myra rejects a
transientNameID, because a per-session identifier cannot be a stable identity key. Accepted formats arepersistent,emailAddress,unspecified,X509SubjectName,kerberos, andWindowsDomainQualifiedName. An omittedFormatdefaults tounspecified.
- Myra rejects a
- Download the IdP signing certificate in PEM (Base64) form.
- Record the IdP entity ID and the IdP SSO URL.
- If the organisation uses Single Logout, record the IdP SLO URL.
- Assign the tenant's users to the application.
Configuring the SAML panel in Myra
- In the tenant edit dialog → Single sign-on (SSO) → SAML 2.0 SSO, enter the IdP values.
- In the IdP entity ID field, enter the identity provider's entity ID.
- In the IdP SSO URL field, enter the identity provider's SSO URL.
- In the IdP signing certificate (PEM) field, paste the signing certificate.
- A SAML signing certificate is public, so Myra stores and returns it in full.
- In the NameID format drop-down list, select the format that matches the identity provider.
- The drop-down offers
persistent,emailAddress,X509SubjectName,kerberos, andWindowsDomainQualifiedName. Selectpersistentfor a stable object identifier oremailAddressfor an email NameID. The backend also acceptsunspecified(Microsoft Entra's default) even though the drop-down omits it — the assertion's ownFormatis validated independently of this selection.
- The drop-down offers
- In the Allowed email domains field, enter the permitted domains.
- This is the verified-domain allowlist.
- If the organisation uses Single Logout, enter the IdP SLO URL in the Single Logout URL field.
- The Single Logout endpoint appears in the SP metadata only when this field is set.
- If the organisation requires signed authentication requests, select the Sign authentication
requests option.
- Signed requests use a gateway-wide SP signing key provisioned by the platform operator. If the key is not provisioned, the request path — and inbound Single Logout — fails closed. Provision the key before enabling this option.
- Save the dialog. -> The tenant's users can sign in through the identity provider over SAML.
Trust-boundary rejections
Myra never parses SAML XML in the gateway; an isolated, loopback-only validator verifies every
signature. Myra rejects an unsigned assertion, signature-wrapping, deprecated algorithms (RSA-SHA1),
a wrong signing certificate, an expired or wrong-audience or wrong-recipient condition, a missing
InResponseTo (an identity-provider-initiated assertion is not accepted at the ACS), and a
non-identity NameID. Assertion timestamps are validated with a ±120-second clock-skew tolerance. For
the full contract, see
Admin API authentication.
Single Logout
When the tenant configures the Single Logout URL and the user signed in through SAML, Myra
propagates a sign-out to the identity provider so the directory session also ends. An inbound Single
Logout message must carry a valid signature; an unsigned or forged LogoutRequest is rejected. Myra
clears the caller's own local session cookie in every case, but propagates to the identity provider
and grants trust only on a verified signature.