Fields will unroll underneath. Copy the link under Assertion consumer service URL (ACS) by clicking on the copy/paste icon to the right.
Copy the Assertion consumer service URL to enable SAML.
Go back to your Azure portal.
Under Assertion Consumer Service URL, paste the URL from Chatlayer.
Under SAML Signing Certificate, click on Download to download the certificate.
Download the SAML Base64 certificate.
Open the certificate on the side with a text editor.
From the text editor, copy the value of the certificate.
Back to Chatlayer, paste this value under Public certificate.
Back to Azure: under Set up Chatlayer, copy and paste the Azure Login URL under the Sign on URL on Chatlayer.
Do the same for the identifier: copy and paste the Azure AD Identifier under the Issuer field on Chatlayer.
Copy and paste the Login and Identifier from Azure to Chatlayer.
On Chatlayer, you should have the following fields filled:
Copy and paste the needed fields on Chatlayer.
Save your changes on Chatlayer.
Save your changes on Azure AD.
It is now possible for members of your AD organization to login to the Chatlayer application.
We do not currently offer role-mapping of Azure AD roles to Chatlayer roles. You can find out more about roles and access control on our user management page.
With Okta
To set up SAML SSO through Okta:
Create a new app integration in Okta.
Select SAML 2.0.
Create an app with SAML 2.0 on Okta.
Give the newly created SAML 2.0 app a name.
Fill in the Single sign on URL as retrieved from Chatlayer (Assertion consumer service URL) and the Audience URI (https://auth.chatlayer.ai/auth/realms/Chatlayer)
Select the following settings in the 'Feedback' step of the Okta configuration:
Require SAML SSO for all
At the bottom of your Team page, under your SAML single sign-on toggle, you have the option to turn on a Require SAML SSO authentification for all members.
Turn on this toggle
If you turn on this toggle, the only people that will have access to the bot are the ones that have an SSO.
Therefore, the toggles for SSO offer two options:
Either the first toggle is on, and the second toggle isn't: users that have SSO will be able to login to the bot and others just with their own credentials.
Or the two toggles are on: only users that have SSO will be able to login to your bot.