Apidog supports Mapping an identity provider (IdP)'s group to a team within an Apidog organization via SAML.Here is a step-by-step video tutorial using Microsoft Entra ID:Adding the groups attribute#
Configure your IdP to include the user's groups in a SAML attribute named groups.Microsoft Entra ID#
1.
Open the Microsoft Entra ID management portal.
2.
Go to Enterprise applications and open your Apidog application.
3.
On the application's Overview page, click Set up single sign on, then edit Attributes & Claims.
4.
Click Add a group claim and select the groups to include.
5.
Select Customize the name of the group claim and set the name to groups.
Microsoft Entra ID sends the selected groups' object IDs in the SAML assertion.Okta#
1.
In Okta, go to Applications and open the Apidog SAML application.
2.
Open the Sign On tab and edit the SAML attribute statements.
3.
Add a group attribute statement with the following settings:Expression: Configure an expression that includes the groups to map.
Example: user.getGroups({'group.id': {'00gGROUP_ID_1', '00gGROUP_ID_2'}}).![id]
JumpCloud#
1.
In JumpCloud, go to Access > SSO Applications and open the Apidog application.
2.
On the SSO tab, find the attributes settings.
3.
Enable Include Group Attribute and set Groups Attribute Name to groups.
4.
Save the application and ensure the required user groups are connected to it.
Configuring mapping#
Next, configure the mapping between each IdP group and the required Apidog roles.1.
Identify the group name and the exact value returned for that group in the SAML groups attribute.
| Identity Provider (IdP) | Value to use as the SAML Group ID |
|---|
| Microsoft Entra ID | Group Object ID |
| Okta | Group ID from URL starts with 00g****** |
| JumpCloud | Exact group value returned in the SAML assertion |
For Microsoft Entra ID, you can find the group name and object ID on the Groups page.
For Okta, you can find the group name and ID on the Groups page.
2.
In Apidog, open your organization settings and select SAML Groups.
3.
Add the Group Name and enter its SAML value in SAML Group ID.
4.
Select necessary roles for both organization and Apidog teams that should be assigned to members of the group.
When a user signs in through SSO, Apidog grants team access according to the matching group mappings.Initial project permissions for mapped users#
When a user signs in with SSO and their SAML groups attribute matches a configured SAML group mapping, Apidog adds the user to the mapped teams and assigns initial project permissions for projects in those teams.The initial project permission is derived from the mapped team role:| Mapped team role | Initial project role |
|---|
| Team Admin | Project Maintainer |
| Team Member | Project Readonly |
| Forbidden | Forbidden |
Initial project permissions are applied when the user is synced through SAML group mapping. Apidog creates missing project memberships or updates project memberships with no role.Existing project roles that have already been assigned are not overwritten. For example, if an admin has manually changed a user’s project role, SAML group mapping does not reset that role during later SSO sign-ins.SAML group mapping does not provide a separate per-project role setting. To change a user’s project role, update the project member permissions after the user has been added to the team.If a user is no longer included in a mapped SAML group, Apidog may remove the user from the corresponding team during SAML sync. When the team membership is removed, the user’s project memberships in that team are also removed.