Integrations

/

Keycloak SAML2 SSO with Flexopus

Connect Flexopus to Keycloak via SAML2 and enable your employees to log in securely and centrally managed – without separate access data for Flexopus.

No items found.
No items found.

What is the Keycloak SAML2 SSO integration?

Keycloak is an open-source solution for identity and access management. Keycloak can be connected to Flexopus as a central Identity Provider (IdP) via the SAML 2.0 protocol.

The integration enables Single Sign-On (SSO): Users log in to Keycloak once and automatically gain access to Flexopus – without an additional password. Flexopus acts as a Service Provider (SP) and relies on authentication through Keycloak.

Optionally, additional user attributes such as department, job title or phone number can be passed to Flexopus via SAML2. Group synchronization via the memberOf attribute is also possible.

What is the purpose of integration?

With the Keycloak integration, IT administrators can centrally control who has access to Flexopus. New employees automatically receive a user profile in Flexopus after their first successful SSO login – manual setup is not required.

Typical use cases:

  • Companies that already use Keycloak as their central identity provider can seamlessly integrate Flexopus into their existing authentication infrastructure.
  • Employees log in to Flexopus using their usual company login details – no separate account, no additional password.
  • Groups from Keycloak can be directly imported into Flexopus to control access rights to resources such as desks or rooms.
  • When an employee leaves the company, a simple change in Keycloak is sufficient – access to Flexopus is automatically revoked.

How easy is the integration?

Setup is done via the Keycloak Admin Console and the Flexopus settings under Dashboard > Settings > Authentication. Essentially, a SAML2 app is created in Keycloak, the Flexopus metadata is imported, and then the connection is activated in Flexopus.

The configuration is completed in just a few steps and requires no programming knowledge. Administrators with access to the Keycloak Admin Console can set up the integration independently.

Ready to start? For complete step-by-step setup instructions, please visit our Help Center.

What are the advantages of integration?

  • Centralized access management: Users and permissions are managed exclusively in Keycloak – Flexopus follows automatically.
  • Automatic user setup: New employees receive their Flexopus profile after their first SSO login without any manual effort.
  • Increased security: Keycloak supports multi-factor authentication (MFA), which also applies to Flexopus access.
  • Data minimization: Only the user attributes necessary for Flexopus are transmitted – no superfluous data.
  • Group synchronization: Keycloak groups can be used directly for access management in Flexopus.
  • Seamless user experience: One login for all applications – employees don't need to remember any additional login details.
  • Included free of charge: SSO integration is part of Flexopus and does not require an additional license (depending on the chosen plan).
Categories
Developed By
Flexopus GmbH
Frequently Asked Questions

questions and answers

Are user profiles automatically created in Flexopus?

Yes. By default, a user profile is automatically created in Flexopus after the first successful SAML2 login. This setting can be deactivated if necessary, but is not recommended as it significantly reduces administrative overhead.

What happens when a user is deleted or deactivated in Keycloak?

If a user account in Keycloak is deactivated or deleted, the person in question can no longer log in to Flexopus. Access will be automatically revoked – without any additional steps in Flexopus.

Which user attributes can be passed to Flexopus?

In addition to the mandatory fields (first name, last name, email address and UPN), optionally further attributes such as department, job title, telephone number and cost center can be synchronized via SAML2, provided these are available as fields in Keycloak.

Can I use groups from Keycloak in Flexopus?

Yes. Groups from Keycloak can be passed to Flexopus via the memberOf-SAML2 attribute. These groups are automatically created and updated in Flexopus. They can then be used for access management to resources. Locally in Flexopus, these groups are not editable – Keycloak remains the only source.

Are profile pictures synchronized via SAML2?

No. The SAML2 protocol does not support the transmission of profile pictures. Profile pictures must be uploaded directly to Flexopus by the users.