Skip to content

Generic SAML 2.0 provider

Myra AI Workspace signs users in through any SAML 2.0 identity provider (IdP) — Okta, Auth0, Keycloak, ADFS, and enterprise directories. Myra acts as the SAML service provider (SP). For Microsoft Entra ID, follow the dedicated Microsoft Entra ID guide.

Single sign-on authenticates existing accounts only — provision the users first. Required role: tenant admin or admin (the SSO_MANAGE permission).

Note: The examples use the production admin-API host ai-api-admin.myra.eu. On the integration environment, substitute ai-api-admin-int.myra.eu.


Reading the SP values from Myra

  1. Open Administration → Tenants → the tenant → edit dialog → Single sign-on (SSO).
  2. Select the SAML 2.0 SSO checkbox. -> The panel displays the SP metadata URL and the ACS URL to register at the identity provider. The Logout (SLS) URL follows the same pattern and appears in the served metadata when a Single Logout URL is set.

The SP URLs follow this pattern, where <tenant-id> is the Myra tenant UUID (the id from the tenant list, not the slug):

IdP field Myra SP value
Entity ID / Identifier https://ai-api-admin.myra.eu/admin/auth/saml/<tenant-id>/metadata
Assertion Consumer Service (ACS) / Reply URL https://ai-api-admin.myra.eu/admin/auth/saml/<tenant-id>/acs
Single Logout Service (SLS) / Logout URL https://ai-api-admin.myra.eu/admin/auth/saml/<tenant-id>/sls

These URLs are served on the admin-API host over HTTPS, not on the application host ai.myra.eu. The SP metadata document at the metadata URL is authoritative.

Note: Register the values exactly as the Myra panel and the SP metadata show them. A host or scheme mismatch causes the identity provider to reject the assertion.

Registering the SP at the identity provider

  1. Create a new SAML application at the identity provider.
  2. Enter the Myra Entity ID, ACS URL, and Logout URL from the table above.
  3. Set the NameID (the unique user identifier) to a stable value — the user's email address or a persistent object identifier.
    • Myra rejects a transient NameID, because a per-session identifier cannot be a stable identity key. Accepted formats are persistent, emailAddress, unspecified, X509SubjectName, kerberos, and WindowsDomainQualifiedName. An omitted Format defaults to unspecified.
  4. Download the IdP signing certificate in PEM (Base64) form.
  5. Record the IdP entity ID and the IdP SSO URL.
  6. If the organisation uses Single Logout, record the IdP SLO URL.
  7. Assign the tenant's users to the application.

Configuring the SAML panel in Myra

  1. In the tenant edit dialog → Single sign-on (SSO) → SAML 2.0 SSO, enter the IdP values.
  2. In the IdP entity ID field, enter the identity provider's entity ID.
  3. In the IdP SSO URL field, enter the identity provider's SSO URL.
  4. In the IdP signing certificate (PEM) field, paste the signing certificate.
    • A SAML signing certificate is public, so Myra stores and returns it in full.
  5. In the NameID format drop-down list, select the format that matches the identity provider.
    • The drop-down offers persistent, emailAddress, X509SubjectName, kerberos, and WindowsDomainQualifiedName. Select persistent for a stable object identifier or emailAddress for an email NameID. The backend also accepts unspecified (Microsoft Entra's default) even though the drop-down omits it — the assertion's own Format is validated independently of this selection.
  6. In the Allowed email domains field, enter the permitted domains.
    • This is the verified-domain allowlist.
  7. If the organisation uses Single Logout, enter the IdP SLO URL in the Single Logout URL field.
    • The Single Logout endpoint appears in the SP metadata only when this field is set.
  8. If the organisation requires signed authentication requests, select the Sign authentication requests option.
    • Signed requests use a gateway-wide SP signing key provisioned by the platform operator. If the key is not provisioned, the request path — and inbound Single Logout — fails closed. Provision the key before enabling this option.
  9. Save the dialog. -> The tenant's users can sign in through the identity provider over SAML.

Trust-boundary rejections

Myra never parses SAML XML in the gateway; an isolated, loopback-only validator verifies every signature. Myra rejects an unsigned assertion, signature-wrapping, deprecated algorithms (RSA-SHA1), a wrong signing certificate, an expired or wrong-audience or wrong-recipient condition, a missing InResponseTo (an identity-provider-initiated assertion is not accepted at the ACS), and a non-identity NameID. Assertion timestamps are validated with a ±120-second clock-skew tolerance. For the full contract, see Admin API authentication.

Single Logout

When the tenant configures the Single Logout URL and the user signed in through SAML, Myra propagates a sign-out to the identity provider so the directory session also ends. An inbound Single Logout message must carry a valid signature; an unsigned or forged LogoutRequest is rejected. Myra clears the caller's own local session cookie in every case, but propagates to the identity provider and grants trust only on a verified signature.