
Shibboleth SAML2 SSO with Flexopus: Secure single sign-on for your organization
With SAML2 integration in Flexopus, you enable your employees to log in securely and conveniently – without additional passwords, directly via your organization's existing identity infrastructure.
What is the Shibboleth SAML2 SSO integration?
The integration is based on the open SAML2 standard (Security Assertion Markup Language 2.0). Flexopus acts as a Service Provider (SP), while Shibboleth, as an Identity Provider (IdP), handles the authentication.
Upon login, Flexopus redirects the user to the Shibboleth IdP. There, the identity is verified and a signed SAML2 assertion is sent back to Flexopus. Flexopus reads the relevant user attributes from this assertion – such as name, email address, department or cost center – and logs in the user.
Shibboleth is widely used in academia and the public sector and supports fine-grained access controls as well as multi-factor authentication. Since Flexopus fully implements the SAML2 standard, it is possible to connect to any SAML2-compliant Identity Provider – including Shibboleth.
What is the purpose of integration?
With the Shibboleth SAML2 SSO integration, your employees log in to Flexopus with their existing organizational data – without a separate account or additional password.
Typical use cases for integration:
- Employees log in to Flexopus using their existing university or company login details.
- New users are automatically created in Flexopus upon their first login – without manual preparation.
- User attributes such as name, email, department or cost center are transferred directly from the Shibboleth IdP.
- Access to Flexopus can be centrally controlled via the Identity Provider – individually or via user groups.
- Password login can optionally be disabled to enforce SSO as the only login method.
How easy is the integration?
The setup is done entirely via the Flexopus dashboard and requires no programming. As an administrator, navigate to the authentication settings, create a new SAML2 provider, and exchange the metadata with your Shibboleth IdP.
Next, you configure the attribute mappings – that is, which fields from the IdP (e.g., First name, last name, email) will be passed to Flexopus. Next, you specify which users or groups should have access and test the connection.
For complete step-by-step setup instructions, please visit our Help Center.
What are the advantages of integration?
- No additional password required: Employees use their existing login details – this reduces password management and support effort.
- Automatic user creation: New users are automatically registered in Flexopus upon their first SSO login.
- Central access management: Access to Flexopus is controlled directly in the Shibboleth IdP – changes take effect immediately.
- Multi-factor authentication support: Your organization's security policies will automatically apply to Flexopus as well.
- Data minimization: Only the attributes actually needed for the operation of Flexopus are transferred.
- Multiple identity providers possible: Organizations with multiple units can configure multiple SSO providers simultaneously.
- Included free of charge: SAML2 SSO integration is (depending on the chosen plan) part of Flexopus and does not require an additional license.
Further integrations
questions and answers
Which user attributes are transferred from Shibboleth to Flexopus?
Required attributes are first name, last name (or a combined name field) and email address. Optionally, additional fields such as department, job title, cost center or group memberships (memberOf) can be transferred. Flexopus supports common URN-based attribute mappings, as typically used in Shibboleth.
What happens if a user doesn't yet have an account in Flexopus?
By default, a new user account is automatically created upon the first successful SSO login. No manual preparation is required. This automatic registration can be disabled in the security settings if needed.
How is it ensured that only authorized users have access?
Access is controlled centrally in your Shibboleth IdP. There, you define which users or groups have access to Flexopus – either for all users or specifically for certain groups. Additionally, you can configure allowed domains in Flexopus to further restrict access.
Can I disable password login after setting up SSO?
Yes. In Flexopus' authentication settings, you can completely disable password login or hide the login form. This ensures that all users log in exclusively via SSO. A hidden backup login remains accessible to administrators.
What happens if the user ID (UPN) changes?
The User Principal Name (UPN) is a unique and unchanging identifier. Changing the UPN subsequently can lead to duplicate user entries. If this is still necessary, please contact Flexopus support. It is therefore recommended to choose the UPN carefully from the start and not to change it afterwards.

