SAML integration with Keycloak

This guide describes how to configure Keycloak as a SAML 2.0 Identity Provider (IdP) for ClouDNS.

Step 1: Create a Realm in Keycloak

Log in to the Keycloak Administration Console and create a new realm, or use an existing realm for the ClouDNS integration.

SettingValue
Realm name cloudns

It is recommended to use a public HTTPS address for your Keycloak installation.

Example:
https://sso.example.com

Step 2: Create a SAML Client

Select the appropriate realm and navigate to:

Clients > Create client

Configure the new client as follows:

SettingValue
Client type SAML
Client ID https://www.cloudns.net
Name ClouDNS

Click Save.

Step 3: Configure the SAML Client

Access settings

Open the newly created ClouDNS client and configure the following initial values:

SettingValue
Master SAML Processing URL https://www.cloudns.net
Valid Redirect URIs https://www.cloudns.net/*
These are temporary values. After adding the SAML provider to ClouDNS, replace them with the ACS URL generated by ClouDNS.

SAML capabilities

SettingValue
Name ID Format email
Force Name ID Format On
Force POST Binding On
Include AuthnStatement On

Signature and Encryption

SettingValue
Sign Documents On
Sign Assertions Off
Signature Algorithm RSA_SHA256

Keys

Open the Keys tab and configure:

SettingValue
Client Signature Required Off
Encrypt Assertions Off

Step 4: Download the Keycloak SAML Metadata

Keycloak provides the SAML Identity Provider metadata through the following endpoint:

https://sso.example.com/realms/cloudns/protocol/saml/descriptor

Replace sso.example.com and cloudns with your actual Keycloak hostname and realm name.

Recommended method

We recommend downloading the metadata XML directly with curl instead of using the browser's Save Page function.

This ensures that the downloaded file contains the original XML response without any browser-generated HTML or additional content.

curl -fsS \
"https://sso.example.com/realms/cloudns/protocol/saml/descriptor" \
-o keycloak-metadata.xml

You can optionally validate the downloaded XML before uploading it:

xmllint --noout keycloak-metadata.xml

If the XML file is valid, the command will complete without displaying an error.

Step 5: Add Keycloak as a SAML Provider in ClouDNS

Log in to your ClouDNS account and navigate to:

Profile > SSO Authentication

Click Add new provider and enter a name for the provider.

SettingValue
Provider name Keycloak
Metadata XML keycloak-metadata.xml

After adding the provider, ClouDNS will generate an ACS URL similar to:

https://www.cloudns.net/saml/user/XXXXX

Copy this URL. It will be required in the next step.

Step 6: Configure the ClouDNS ACS URL in Keycloak

Return to:

Clients > ClouDNS > Settings

Replace the temporary values configured earlier with the ACS URL generated by ClouDNS.

SettingValue
Master SAML Processing URL https://www.cloudns.net/saml/user/XXXXX
Valid Redirect URIs https://www.cloudns.net/saml/user/XXXXX

Replace XXXXX with the value generated for your ClouDNS account.

Fine Grain SAML Endpoint Configuration

You can also explicitly configure the ACS endpoint under:

Advanced > Fine Grain SAML Endpoint Configuration

SettingValue
Assertion Consumer Service POST Binding URL https://www.cloudns.net/saml/user/XXXXX

Click Save.

Step 7: Configure Keycloak Users

Create or configure the users who should be able to access ClouDNS through SAML.

Each user must have a valid email address configured in Keycloak. The email address should correspond to the user account allowed to access ClouDNS.

SettingExample
Username user
Email user@example.com
Email verified Yes

Step 8: Test the SAML Login

Open the ClouDNS login page and select the configured SAML provider.

You should be redirected to Keycloak for authentication. After successful authentication, Keycloak will send the signed SAML response to the ClouDNS ACS URL and you will be logged in to your ClouDNS account.

Optional: Display ClouDNS in the Keycloak Account Console

If you want ClouDNS to appear in the Keycloak Account Console under Applications, open the ClouDNS client settings and enable:

SettingValue
Always Display in Console On

The Keycloak Account Console is available at:

https://sso.example.com/realms/cloudns/account/

Last modified: 2026-10-06
We value your privacy! We use cookies to enhance your browsing experience, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie Policy.