Skip to main content
You need administrative access to both K16 and your SAML identity provider.

Values K16 provides

After you select SAML, the Service provider values panel shows:
  • SP entity ID
  • SAML ACS URL
  • SAML logout URL
Configure the entity ID and assertion consumer service URL in your identity provider. Configure the logout URL only when you enable single logout.

Create the provider

1

Choose SAML

Open Settings > Single sign-on > New identity provider, then select SAML.
2

Name the provider

Enter Provider name. You cannot rename the provider later.
3

Choose a metadata method

Leave Upload metadata XML on to paste the provider’s metadata. Turn it off to enter an HTTPS Metadata URL instead.
4

Map email

Enter the identity-provider attribute that carries the user’s email address in Email attribute mapping.
5

Configure optional trust and logout

Download the SP signing certificate only when your identity provider requires the public certificate. Turn on Enable IdP sign-out (SLO) only when the provider metadata includes a supported logout service.
6

Create and test

Review Enabled for sign-in, select Create, assign a pilot user in the identity provider, and test the normal K16 sign-in flow.
The metadata upload choice is locked after creation in the current editor. Create a replacement provider if you must switch between uploaded metadata and a metadata URL.

Email mapping requirements

The mapped assertion value must resolve to the same email identity K16 expects for the user. If your identity provider uses a custom claim, enter that claim’s exact name.

Edit a SAML provider

Select the provider in Settings > Single sign-on. You can update metadata content, email mapping, Enabled for sign-in, and Enable IdP sign-out (SLO). Select Save changes.
Keep an authorized administrator session open while testing. If the new configuration fails, disable or correct the provider from that existing session and contact K16 Support when needed.
See Troubleshoot SSO.
Last modified on September 16, 2026