This help page is for users in Creator 6. If you are in the older version (Creator 5), click here. Know your Creator version.In Zoho Creator, Portal administrator can simplify password management for their portal users using SAML. If the administrator already stores the login credentials of their portal users in a SAML provider then they can configure the Portal to be authenticated based on these credentials. The administrator can also configure SAML for multiple portals to enable portal users access all the portals using the same credentials.
When a portal user accesses the portal URL, it will be redirected to the configured login URL for authentication. The Identity Provider (IDP) returns back SAML response specific to that portal user after successful validation. The received response will be decoded based on the configured public key. If the response indicates successful authentication, the portal user will be logged into the portal.
Before configuring SAML, it is important to understand the key concepts involved in this authentication process:
Term | Description |
Identity Provider (IDP) | The system that manages user identities and credentials. The IDP authenticates users and sends SAML responses to Zoho Creator. |
Service Provider (SP) | A unique identifier that enables Zoho Creator Portal and the Identity Provider to recognize each other. For example, Zoho Creator uses zoho.com for US customers, zoho.eu for EU customers, and zoho.com.cn for China customers. |
Entity ID | A unique identifier that enables Zoho Creator Portal and the Identity Provider to recognize each other. For example, Zoho Creator uses zoho.com for US customers, zoho.eu for EU customers, and zoho.com.cn for China customers. |
ACS URL (Assertion Consumer Service URL) | The format used to identify users in the SAML response sent by the Identity Provider to the Service Provider via ACS URL. Zoho Creator supports only the email address format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress This must be specified in the Identity Provider to ensure proper authentication. |
Login URL | The Identity Provider’s login URL where portal users are redirected for authentication. |
Logout URL | Configured in the Zoho Creator portal, this is the URL where users are redirected after the Identity Provider completes the SAML logout process. |
Service Provider Logout URL | Configured in the Identity Provider (IDP), this URL is triggered when a user clicks Sign out in the Zoho Creator portal. The IDP uses this endpoint to terminate the user’s SAML session and log the user out from all connected applications. |
Key | A certificate or cryptographic key provided by the Identity Provider (IDP) that Zoho Creator uses to verify the authenticity and integrity of the SAML response. This ensures the authentication response is secure and valid. |
Algorithm | The cryptographic algorithm used to sign and verify SAML response. Zoho Creator supports standard algorithms such as RSA or DSA. The selected algorithm determines how the SAML response is signed or encrypted, and must match the configuration in the IDP. |
Scenario 1 - Configure SAML for multiple portals: Consider an organization named Zylker whose customers have unique login credentials. Zylker has multiple portals in Zoho creator which has to be accesssed by its customers. To access all the portals the customers has to create multiple login credentials for each portal. But this cumbersome process can be overcome by using SAML authentication. Zylker has to upload the login credentials of all its customers to a third party SAML provider. Zylker can configure SAML in all of its portals and ensure a Single Sign on mechanism for the customers. So when the customers try to access the Zoho Creator portal their login credentials will be authenticated by the third party SAML providers(Like OneLogin, ADFS etc).
Scenario 2 - Configure SAML authentication for already existing portal users: The organisation Zylker has two different portals in Zoho Creator. The portal users of each of the portals have been assigned login credentials specific to that portal. Zylker configures the SAML authentication in order to give the portal users’ a single sign on mechanism. Now when the portal users tries to access the portal they will have to be authenticated by the SAML provider. Their old login credentials will be overridden and only the credentials uploaded in the SAML provider will authenticate the portal users.
Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.
If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.
All-in-one knowledge management and training platform for your employees and customers.
You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.