SAML 2.0 · runtime configuration
Configure SAML.
Set the identity-side inputs here instead of editing .env. Changes apply
immediately and are saved to a local file, so they survive a restart. An empty field falls
back to its environment default. The live route stays /saml/acs —
the ACS field only changes the URL advertised to the IdP.
SAML is ready — entry point and certificate are both set.
Same thing over the API
# read the effective config
curl https://auth-test.tenantflex.com/saml/config.json
# set it (empty value clears an override)
curl -X POST https://auth-test.tenantflex.com/saml/config \
-H 'content-type: application/json' \
-d '{"entityId":"urn:auth-test-lab","entryPoint":"https://idp/sso","idpCert":"MIID..."}'
# revert everything to the .env baseline
curl -X POST https://auth-test.tenantflex.com/saml/config/reset