auth test lab saml oidc json setup

SAML 2.0 · runtime configuration

Configure SAML.

Set the identity-side inputs here instead of editing .env. Changes apply immediately and are saved to a local file, so they survive a restart. An empty field falls back to its environment default. The live route stays /saml/acs — the ACS field only changes the URL advertised to the IdP.

SAML is ready — entry point and certificate are both set.
The SP identifier. Entra calls it the Identifier; Okta the Audience URI; PingOne the ACS/Entity ID.
Where the app sends you to sign in. Required. PingOne: the connection's Single Sign-On Service URL.
Paste the PEM or the bare base64 body — line breaks and indentation are fine. Required. It is validated as X.509 before being accepted.
In effect: CN=TF Demo SAML
valid Oct 4 11:14:10 2026 GMT → Oct 4 11:24:10 2029 GMT
sha256 BD:A5:70:49:10:9F:92:A8:07:75:05:11:09:A3:83:77:3D:AF:C3:71:A7:5E:72:AF:86:F7:3A:CC:95:0F:17:4E
The AssertionConsumerService URL advertised to the IdP. Defaults to https://auth-test.tenantflex.com/saml/acs; override it when running behind a tunnel.
Optional fields
Who the assertion must be addressed to. Defaults to the Entity ID.
The IdP single-logout endpoint. Only needed for SAML single logout.
Leave empty to let the IdP choose.
ADMIN_TOKEN is set, so a token is required to save.
Back to setup
Currently overriding: entityId, entryPoint, idpCert

Same thing over the API

# read the effective config
curl https://auth-test.tenantflex.com/saml/config.json

# set it (empty value clears an override)
curl -X POST https://auth-test.tenantflex.com/saml/config \
  -H 'content-type: application/json' \
  -d '{"entityId":"urn:auth-test-lab","entryPoint":"https://idp/sso","idpCert":"MIID..."}'

# revert everything to the .env baseline
curl -X POST https://auth-test.tenantflex.com/saml/config/reset