From f128106801e474e685a384333f57d866421d655f Mon Sep 17 00:00:00 2001 From: Luiz Felipe Machado <56140722+luizfelmach@users.noreply.github.com> Date: Wed, 1 Apr 2026 10:42:36 -0300 Subject: [PATCH] feat(self-hosting): add SAML SSO env config and open Kong routes (#43385) --- .../self-hosting/self-hosted-saml-sso.mdx | 20 ++++++++----- docker/.env.example | 29 ++++++++++++++++--- docker/docker-compose.yml | 8 +++++ docker/volumes/api/kong.yml | 20 +++++++++++++ 4 files changed, 66 insertions(+), 11 deletions(-) diff --git a/apps/docs/content/guides/self-hosting/self-hosted-saml-sso.mdx b/apps/docs/content/guides/self-hosting/self-hosted-saml-sso.mdx index a8dfafce877..ee94aa39bd5 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-saml-sso.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-saml-sso.mdx @@ -379,15 +379,17 @@ curl 'http:///auth/v1/admin/sso/providers' \ -H 'apikey: your-service-role-key' ``` -Filter by resource ID: +Filter by resource ID using exact match: ```sh -# Exact match curl 'http:///auth/v1/admin/sso/providers?resource_id=my-idp' \ -H 'Authorization: Bearer your-service-role-key' \ -H 'apikey: your-service-role-key' +``` -# Prefix match +or prefix match: + +```sh curl 'http:///auth/v1/admin/sso/providers?resource_id_prefix=prod-' \ -H 'Authorization: Bearer your-service-role-key' \ -H 'apikey: your-service-role-key' @@ -467,18 +469,22 @@ Both methods return an object with a `url` property - redirect the user to this ### Using the REST API directly +By domain: + ```sh -# By domain -curl -X POST 'http:///sso' \ +curl -X POST 'http:///auth/v1/sso' \ -H 'Content-Type: application/json' \ -H 'apikey: your-anon-key' \ -d '{ "domain": "example.com", "skip_http_redirect": true }' +``` -# By provider ID -curl -X POST 'http:///sso' \ +By provider ID: + +```sh +curl -X POST 'http:///auth/v1/sso' \ -H 'Content-Type: application/json' \ -H 'apikey: your-anon-key' \ -d '{ diff --git a/docker/.env.example b/docker/.env.example index 81b7c8e9c47..b84a8e777d2 100644 --- a/docker/.env.example +++ b/docker/.env.example @@ -166,7 +166,7 @@ ENABLE_PHONE_AUTOCONFIRM=true ## OAuth / Social login providers # Uncomment and fill in the providers you want to enable. -# You must ALSO uncomment the matching GOTRUE_EXTERNAL_* lines in docker-compose.yml. +# You must ALSO uncomment the matching GOTRUE_EXTERNAL_* lines in docker-compose.yml # Documentation: https://supabase.com/docs/guides/self-hosting/self-hosted-oauth # GOOGLE_ENABLED=false # GOOGLE_CLIENT_ID= @@ -182,7 +182,7 @@ ENABLE_PHONE_AUTOCONFIRM=true # Phone / SMS provider configuration # Uncomment to configure SMS delivery for phone auth and phone MFA. -# You must ALSO uncomment the matching GOTRUE_SMS_* lines in docker-compose.yml. +# You must ALSO uncomment the matching GOTRUE_SMS_* lines in docker-compose.yml # Documentation: https://supabase.com/docs/guides/self-hosting/self-hosted-phone-mfa # SMS_PROVIDER=twilio # SMS_OTP_EXP=60 @@ -200,7 +200,7 @@ ENABLE_PHONE_AUTOCONFIRM=true # Multi-factor authentication (MFA) # Uncomment to change MFA defaults. -# You must ALSO uncomment the matching GOTRUE_MFA_* lines in docker-compose.yml. +# You must ALSO uncomment the matching GOTRUE_MFA_* lines in docker-compose.yml # App Authenticator (TOTP) - enabled by default # MFA_TOTP_ENROLL_ENABLED=true @@ -210,9 +210,30 @@ ENABLE_PHONE_AUTOCONFIRM=true # MFA_PHONE_ENROLL_ENABLED=false # MFA_PHONE_VERIFY_ENABLED=false -## Maximum MFA factors a user can enroll +# Maximum MFA factors a user can enroll # MFA_MAX_ENROLLED_FACTORS=10 +## SAML SSO + +# You must ALSO uncomment the matching GOTRUE_* lines in docker-compose.yml +# Documentation: https://supabase.com/docs/guides/self-hosting/self-hosted-saml-sso + +# SAML_ENABLED=true +# SAML_PRIVATE_KEY= + +# Optional: accept encrypted SAML assertions from IdPs (default: false) +# SAML_ALLOW_ENCRYPTED_ASSERTIONS=false + +# Optional: how long relay state tokens remain valid (default: 2m0s) +# SAML_RELAY_STATE_VALIDITY_PERIOD=2m0s + +# Optional: override the SAML entity ID / ACS base URL +# Defaults to API_EXTERNAL_URL if not set +# SAML_EXTERNAL_URL=https://supabase.example.com:8000 + +# Optional: rate limit on the ACS endpoint (requests per second, default: 15) +# SAML_RATE_LIMIT_ASSERTION=15 + ############ # Storage - Configuration for Storage diff --git a/docker/docker-compose.yml b/docker/docker-compose.yml index 6a026b87607..98469e9c7d5 100644 --- a/docker/docker-compose.yml +++ b/docker/docker-compose.yml @@ -220,6 +220,14 @@ services: # GOTRUE_MFA_PHONE_VERIFY_ENABLED: ${MFA_PHONE_VERIFY_ENABLED} # GOTRUE_MFA_MAX_ENROLLED_FACTORS: ${MFA_MAX_ENROLLED_FACTORS} + # SAML SSO + # GOTRUE_SAML_ENABLED: ${SAML_ENABLED} + # GOTRUE_SAML_PRIVATE_KEY: ${SAML_PRIVATE_KEY} + # GOTRUE_SAML_ALLOW_ENCRYPTED_ASSERTIONS: ${SAML_ALLOW_ENCRYPTED_ASSERTIONS} + # GOTRUE_SAML_RELAY_STATE_VALIDITY_PERIOD: ${SAML_RELAY_STATE_VALIDITY_PERIOD} + # GOTRUE_SAML_EXTERNAL_URL: ${SAML_EXTERNAL_URL} + # GOTRUE_SAML_RATE_LIMIT_ASSERTION: ${SAML_RATE_LIMIT_ASSERTION} + # Uncomment to enable custom access token hook. # See: https://supabase.com/docs/guides/auth/auth-hooks for # full list of hooks and additional details about custom_access_token_hook diff --git a/docker/volumes/api/kong.yml b/docker/volumes/api/kong.yml index ef830713234..b89e868f557 100644 --- a/docker/volumes/api/kong.yml +++ b/docker/volumes/api/kong.yml @@ -78,6 +78,26 @@ services: plugins: - name: cors + - name: auth-v1-open-sso-acs + url: "http://auth:9999/sso/saml/acs" + routes: + - name: auth-v1-open-sso-acs + strip_path: true + paths: + - /sso/saml/acs + plugins: + - name: cors + + - name: auth-v1-open-sso-metadata + url: "http://auth:9999/sso/saml/metadata" + routes: + - name: auth-v1-open-sso-metadata + strip_path: true + paths: + - /sso/saml/metadata + plugins: + - name: cors + ## Secure Auth routes - name: auth-v1 _comment: 'Auth: /auth/v1/* -> http://auth:9999/*'