管理与治理
Set up Okta Workforce Identity SAML
Set up SAML SSO in n8n with Okta.
Prerequisites
You need an Okta Workforce Identity account, and the redirect URL and entity ID from n8n's SAML settings.
Okta Workforce may enforce two factor authentication for users, depending on your Okta configuration.
Read the Set up SAML guide first.
Setup
In addition to the following instructions, this visual step-by-step guide shows how to set up SAML in n8n with Okta:
Visual step-by-step guide for setting up SAML with Okta
- In your Okta admin panel, select Applications > Applications.
- Select Create App Integration. Okta opens the app creation modal.
- Select SAML 2.0, then select Next.
- On the General Settings tab, enter
n8nas the App name. - Select Next .
- On the Configure SAML tab, complete the following General fields:
- Single sign-on URL: the Redirect URL from n8n.
- Audience URI (SP Entity ID): the Entity ID from n8n.
- Default RelayState: leave this empty.
- Name ID format:
EmailAddress. - Application username:
Okta username. - Update application username on:
Create and update.
- Create Attribute Statements:
| Name | Name format | Value |
|---|---|---|
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/firstname |
URI Reference | user.firstName |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/lastname |
URI Reference | user.lastName |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn |
URI Reference | user.login |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress |
URI Reference | user.email |
- Select Next. Okta may prompt you to complete a marketing form, or may take you directly to your new n8n Okta app.
- Assign the n8n app to people:
- On the n8n app dashboard in Okta, select Assignments.
- Select Assign > Assign to People. Okta displays a modal with a list of available people.
- Select Assign next to the person you want to add. Okta displays a prompt to confirm the username.
- Leave the username as email address. Select Save and Go Back.
- Select Done.
- Get the metadata XML: on the Sign On tab, copy the Metadata URL. Navigate to it, and copy the XML. Paste this into Identity Provider Settings in n8n.
- Select Save settings.
- Select Test settings. n8n opens a new tab. If you're not currently logged in, Okta prompts you to sign in. n8n then displays a success message confirming the attributes returned by Okta.
Instance and project access provisioning
n8n supports two ways to provision instance and project roles via SSO. Choose one based on where you want the mapping logic to live:
- Map rules on your IdP: configure n8n-specific attributes (
n8n_instance_roleandn8n_projects) in Okta, and n8n reads them directly from the SAML response. Steps below. - Map rules inside n8n: send group membership from Okta as a SAML attribute, and define mapping expressions inside n8n. No n8n-specific configuration is needed in Okta beyond the group attribute. See Map rules inside n8n on the main SAML setup page.
In n8n, set Role assignment to Instance roles via SSO or Instance and project roles via SSO, then choose your preferred Role mapping method.
Map rules on your IdP
Adding the required attributes
- In your Okta admin panel, select Applications > Applications.
- Go to the configuration of your n8n application
- On the General tab, click Edit next to SAML Settings
- In the page that opens, continue to step 2: Configure SAML
- Add the following two Attribute Statements:
| Name | Name format | Value |
|---|---|---|
| n8n\_instance\_role | Basic | appuser.n8n\_instance\_role |
| n8n\_projects | Basic | appuser.n8n\_projects |
- Click Next
- Click Finish
Updating the app profile
- In your Okta admin panel, select Directory > Profile Editor.
- Go to the profile of your n8n application
- Click Add Attribute
- Add the n8n\_instance\_role attribute
- Data type: string
- Display name: n8n\_instance\_role
- Variable name: n8n\_instance\_role
- Attribute type: Group
- Add the n8n\_projects attribute
- Data type: string array
- Display name: n8n\_projects
- Variable name: n8n\_projects
- Attribute type: Group
- Group priority: Combine values across groups
Now when you go to Directory > Groups and edit the assigned n8n application, you can configure the n8n\_instance\_role and n8n\_projects to be sent to n8n upon logging in via SAML.
官方原文和授权
本页来自 N8N 英文官方网站固定快照,并转换成 xueai 静态页面。内容以 N8N 持续更新的官方页面为准。