auth test lab saml oidc setup

SAML 2.0 & OpenID Connect

One bench,
both protocols.

Register this as a SAML service provider and an OIDC client, sign in over each, and every claim the IdP delivers lands in one table. Then move the app to a new IdP and sign in again: the compare view lines up the sign-in from before the migration against the one after, by meaning rather than by name, and shows what changed — the subject identifier, a claim that vanished, groups that came back as IDs instead of names.

SAML 2.0

ready
Entity IDEntra: Identifier · Okta: Audience URI https://auth-test.tenantflex.com/saml/metadata
Reply URLEntra: Reply URL · Okta: Single sign-on URL https://auth-test.tenantflex.com/saml/acs
Sign-out URL https://auth-test.tenantflex.com/saml/slo
MetadataUpload this instead of typing https://auth-test.tenantflex.com/saml/metadata
  • ✓ SAML_ENTRY_POINT https://trial-3394347.okta.com/app/trial-3394347_tfdemosaml_1/exk18cdjgntW2SUDH698/sso/saml
  • ✓ SAML_IDP_CERT Loaded. Assertion signatures will be checked against it.
  • – SP key pair Optional. Run npm run cert if the IdP wants signed requests or sends encrypted assertions.

OpenID Connect

ready
Redirect URIEntra: Redirect URI · Okta: Sign-in redirect URI https://auth-test.tenantflex.com/oidc/callback
Post-logout URIOkta: Sign-out redirect URI https://auth-test.tenantflex.com/oidc/signed-out
Client type confidential — client_secret_post
Scopes requested openid profile email offline_access
  • ✓ OIDC_ISSUER https://trial-3394347.okta.com
  • ✓ OIDC_CLIENT_ID 0oa18cdhh93p0vlZL698
  • ✓ Discovery Read from https://trial-3394347.okta.com/.well-known/openid-configuration

IdP migration

Moving an application to a new IdP? Sign in, save it as before, point the app at the new IdP, sign in again and save that as after. Each protocol is compared against itself.

SAML 2.0

ready to compare
before
https://sts.windows.net/b164ba84-e972-477c-9709-7b1d0fb7d0c1/ · Lee Gov
after
http://www.okta.com/exk18cdjgntW2SUDH698 · Lee McGovern

OpenID Connect

ready to compare
before
https://login.microsoftonline.com/b164ba84-e972-477c-9709-7b1d0fb7d0c1/v2.0 · Lee Gov
after
https://trial-3394347.okta.com · Lee McGovern