# Keycloak

> Part of the NocoDB documentation (Product docs). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/saml-sso/keycloak
Last updated: 2026-09-25

Learn how to configure Keycloak as an identity provider for NocoDB.

This article briefs about the steps to configure Keycloak as Identity service provider for NocoDB

### NocoDB, Retrieve `SAML SSO` Configuration details

1. Go to `Account Settings`
2. Select `Authentication (SSO)`
3. Click on `New Provider` button
4. On the Popup modal, Specify a `Display name` for the provider; note that, this name will be used to display the provider on the login page
5. Retrieve `Redirect URL` & `Audience / Entity ID`; these information will be required to be configured later with the Identity Provider

<img alt="SAML SSO Configuration" src={__img0} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img1} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img2} placeholder="blur" />

### Keycloak, Configure NocoDB as an Application

1. Access your Keycloak account
   * navigate to `Clients` menu
   * select `Clients list` tab > Click `Create client` button.
2. In the `Create Client` modal, `General Settings` tab:
   * Select `SAML` as the `Client type`
   * Specify `Audience/Entity ID` retrieved from NocoDB as the `Client ID`
   * Click `Next`
3. In the `Create Client` modal, `Login Settings` tab,
   * Specify `Redirect URL` retrieved from NocoDB as the `Valid Redirect URIs`
   * Specify `Redirect URL` retrieved from NocoDB as the `Valid post logout redirect URIs`
   * Click `Save`
4. On the `Client details`, `Settings` tab,
   * navigate to `SAML Capabilities` section
   * Specify `Name ID format` as `email`
   * Enable `Force Name ID Format` and `Force POST Binding`
   * navigate to `Signature and Encryption` section
   * Enable `Sign Assertions`
   * Click `Save`
5. On the `Client details`, `Keys` tab,
   * Disable `Signing keys config` > `Client Signature Required`
6. Navigate to `Realm Settings` > `Endpoints`
   * Copy `SAML 2.0 Identity Provider Metadata` URL

### NocoDB, Configure Azure AD as an Identity Provider

1. Go to `Account Settings` > `Authentication` > `SAML`Key
2. Insert `Metadata URL` retrieved in step above; alternatively you can configure XML directly as well
3. `Save`

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

For Sign-in's, user should be able to now see `Sign in with <SSO>` option.

<img alt="SAML SSO Configuration" src={__img4} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with <SSO>` option
</Callout>

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* SAML SSO is available on **NocoDB Cloud** (Business plan and above) and licensed self-hosted deployments (Business plan and above). For access, please reach [**out to sales team**](https://cal.com/nocodb/sales).
* For users on **Business plan**, the SSO configuration menu is available under **Settings** > **Single Sign-On (SSO)** in the workspace sidebar. Refer [here](/docs/product/account-settings/authentication#business-plan) for more details.
* **Domain Verification Required for Cloud Plans**: Before configuring SAML SSO, you must verify your domain in NocoDB (required for both Business and Enterprise plans in the cloud). Only users with email addresses from verified domains can sign in via SSO. See [Domain Verification](/docs/product/account-settings/authentication#domain-verification) for details.
