Note: These instructions cover the basic setup only. Your organisation may have different requirements or specific security policies. If you need assistance or have questions about your specific setup, please reach out to your Atticus account manager or our support team.

SAML Configuration Values

Configure your SAML identity provider with the following values:

Entity ID / Identifier

Use this value for the Entity ID, Identifier, or Audience URI field in your identity provider:

https://app.atticus.tech

Reply URL / ACS URL

Use this value for the Reply URL, Assertion Consumer Service (ACS) URL, or Single Sign-On URL field in your identity provider:

https://app.atticus.tech/api/v1/auth/sso/saml/callback/4aedd0de-48ce-4c70-9d11-2c7156e6df80

Required User Attributes

Name ID (Unique User Identifier)

The Name ID should be set to a persistent, system-generated identifier such as the user's Object ID or internal user ID from your identity provider. This ensures that each user has a stable identifier that will never change — even if their name, email, or other details are updated.

Set the Name ID format to Persistent.

Important: Do not use Employee ID as the Name ID. If you would like to send an Employee ID or other organisational identifier, include it as a separate attribute claim instead (see Optional Attributes below).

Required Attributes

Configure your identity provider to send the following user attributes in the SAML assertion. These attributes allow Atticus to identify and authenticate users properly:

Attribute Name Description
email User's email address
first User's first name / given name
last User's last name / surname

The exact field names in your identity provider may vary. Common mappings include:

  • Email: user.email, user.mail, or user.userprincipalname
  • First Name: user.firstName, user.givenname, or user.givenName
  • Last Name: user.lastName, user.surname, or user.sn

Optional Attributes

If you would like to send an Employee ID, Salary ID, or other organisational identifier to Atticus, you can include it as an additional attribute claim:

Attribute Name Description
employeeId Employee ID or other organisational identifier

Consult with your Atticus account manager if you would like to include additional identifiers.

Sharing Metadata

After configuring your identity provider, you'll need to share the SAML metadata with Atticus. This can typically be provided as:

  • A Metadata URL that Atticus can fetch automatically
  • A Metadata XML file that you download and send to Atticus

Send the metadata URL or XML file to your Atticus account manager or the Atticus platform team to complete the integration.

Need Provider-Specific Instructions? We have detailed step-by-step guides with screenshots for common identity providers: