# Keycloak

> Part of the NocoDB documentation (Product docs). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/saml-sso/keycloak
Last updated: 2026-10-03

Configure Keycloak as a SAML identity provider for NocoDB.

This article gives the steps to configure Keycloak as the identity provider for NocoDB.

### NocoDB, Retrieve `SAML SSO` Configuration details

1. Go to `Account Settings`.
2. Select `Authentication (SSO)`.
3. Click the `New Provider` button.
4. In the dialog, type a `Display name` for the provider. The login page shows the provider with this name.
5. Copy the `Redirect URL` & `Audience / Entity ID`. You need these values later to configure the identity provider.

<img alt="SAML SSO Configuration" src={__img0} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img1} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img2} placeholder="blur" />

### Keycloak, Configure NocoDB as an Application

1. Sign in to your Keycloak account.
   * Go to the `Clients` menu.
   * Select the `Clients list` tab. Click the `Create client` button.
2. In the `Create Client` dialog, on the `General Settings` tab:
   * For the `Client type`, select `SAML`.
   * For the `Client ID`, enter the `Audience/Entity ID` from NocoDB.
   * Click `Next`.
3. In the `Create Client` dialog, on the `Login Settings` tab:
   * For the `Valid Redirect URIs`, enter the `Redirect URL` from NocoDB.
   * For the `Valid post logout redirect URIs`, enter the `Redirect URL` from NocoDB.
   * Click `Save`.
4. On the `Client details` page, on the `Settings` tab:
   * Go to the `SAML Capabilities` section.
   * Set `Name ID format` to `email`.
   * Enable `Force Name ID Format` and `Force POST Binding`.
   * Go to the `Signature and Encryption` section.
   * Enable `Sign Assertions`.
   * Click `Save`.
5. On the `Client details` page, on the `Keys` tab:
   * Disable `Signing keys config` > `Client Signature Required`.
6. Go to `Realm Settings` > `Endpoints`.
   * Copy the `SAML 2.0 Identity Provider Metadata` URL.

### NocoDB, Configure Azure AD as an Identity Provider

1. Go to `Account Settings` > `Authentication` > `SAML`Key
2. Enter the `Metadata URL` from the step above. You can also configure the XML directly.
3. Click `Save`.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

Users now see the `Sign in with <SSO>` option on the sign-in page.

<img alt="SAML SSO Configuration" src={__img4} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with <SSO>` option
</Callout>

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* SAML SSO is available on **NocoDB Cloud** (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach [**out to sales team**](https://cal.com/nocodb/sales).
* On the **Business plan**, the SSO configuration menu is in the workspace sidebar, at **Settings** > **Single Sign-On (SSO)**. For more details, refer [here](/docs/product/account-settings/authentication#business-plan).
* **Domain Verification Required for Cloud Plans**: Verify your domain in NocoDB before you configure SAML SSO. Cloud Business and Enterprise plans both need this. Only users with email addresses from verified domains can sign in with SSO. For details, see [Domain Verification](/docs/product/account-settings/authentication#domain-verification).
