IDP Integrations for SSO - Authentik - Rafay Product Documentation

Authentik

Follow the steps documented below to integrate your Org and Authentik Organizations for Single Sign On (SSO).

Important

Only users with "Organization Admin" privileges can configure SSO in the Rafay Console.


Step 1: Create Group


Step 2: Assign Group to Project


Step 3: Create Group in Authentik


Step 4: Create IdP

Important

Within an org, the domain of an IdP cannot be used for another IdP. A domain existing in an org can be used in multiple orgs (for one IdP in each org)

Important

Encrypting SAML assertions is optional because privacy is already provided at the transport layer using HTTPS. Encrypted assertions provide an additional layer of security on top ensuring that only the SP (Org) can decrypt the SAML assertion.


Step 5: View SP Details

The IdP configuration wizard will display critical information that you need to copy/paste into your Authentik Org. Provide the following information to your Authentik administrator.


Step 6: Create User in Authentik


Step 7: Add User to the Group

Once the user is added to the group, navigate to the Groups page to view the newly added user in the group.


Step 8: Create Application

The Configure SAML Provider page appears


Step 9: Specify IdP Metadata

Copy the "Identity Provider Metadata" URL from the Authentik using the below steps


Step 10: Impersonate the User

Once all configurations are completed, use the Impersonate option to verify the user's access and application view.

Impersonation allows administrators to temporarily log in as a specific user without their credentials. This is useful for validating access, testing SSO configuration, and ensuring the user is mapped correctly to the intended applications.

After impersonating the user, the My Applications page appears, showing the applications assigned to the user's group (e.g., demo-ssogroup).