SAML Overview
Security Assertion Markup Language (SAML) 2.0 is the standard protocol Langdock uses for Single Sign-On (SSO) authentication. With SAML, your users can sign in to Langdock using their existing corporate identity provider credentials.Setup Checklist
Before configuring SAML, complete the following steps:- Navigate to the Security section in your workspace settings

- Ensure you have admin access to your Langdock workspace and your identity provider
- Enable Join by domain

- Add your domain

- Verify your domain before enabling SAML

- Create and configure a SAML application in your identity provider
- Copy the SAML values into Langdock: Issuer, Sign on URL, Certificate, and Audience URI

Continue only after Langdock has verified your domain. You cannot turn on SAML Active before verification is complete.
- Turn on SAML Active

- Test SAML login in a separate browser or incognito window before signing out
Supported Identity Providers
Langdock supports SAML 2.0 with any compatible identity provider. We provide step-by-step guides for:Password Login and SAML
SAML SSO stays required for your verified domains. Turn on Allow External Authentication if you want people outside those domains to sign in with a magic link or another available method. That also covers people you invite through the User Management API. This setting does not open SAML sign-in for arbitrary domains.
Sign SAML requests
Some identity providers require the service provider to sign outgoingAuthnRequest messages so they can verify the request came from Langdock. Turning on Sign SAML requests enables signed AuthnRequests and generates a stable Langdock signing certificate that you upload to your identity provider.
Leave this off unless your identity provider requires signed requests — most Entra ID, Google Workspace, and Okta setups work without it.
To enable request signing:
- In workspace security settings, turn on Sign SAML requests under the SAML configuration.
- Select Download SP certificate to save the Langdock service provider certificate.
- Upload the certificate to your identity provider’s SAML application as the request-verification certificate.
- Test SAML login in an incognito window and confirm the login completes.
The Download SP certificate button only appears after you enable Sign SAML requests. If you rotate or reconfigure the certificate on the identity provider side, re-download it from Langdock to keep both sides in sync.