Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  1. Fotoware Alto
    • 11.14 Schreckhorn
    • Terminology
    • Solutions
    • User Guide - Deutsch
    • User Guide - English
    • API Changelog
  2. Fotoware Veloz
    • Managing users and groups
    • Configuring archives
    • Configuring workflows
    • Configuring site behavior
    • Navigating and searching to find your assets
    • Working with your assets
    • Editing asset metadata
    • Uploading files
    • Version Control in Fotoware
    • Albums - Creating and sharing collections
    • Placing assets in a CMS
    • Working with the Fotoware Pro interface
    • Using the Fotoware plugins
    • Consent management
    • User guide to FotoWeb for iPad (Legacy)
    • Picture conferencing with FotoWeb Screens (Legacy)
    • What's what in Fotoware
    • GDPR
    • Fotoware Veloz releases
    • Activity Exports
    • Fotoware Example Workflows
  3. Fotostation
    • Getting started with Fotostation
    • Viewing, selecting and sorting files
    • Managing your assets with archives
    • Adding metadata to assets
    • Searching for assets
    • Working with your assets
    • Version Control in Fotostation
    • Automating tasks with Actions
    • Configuring metadata fields and editors
    • Configuring Fotostation
    • Configuring Fotostation for multi-user environments
    • Troubleshooting Fotostation
  4. Fotoware Flow
    • What is Flow?
    • Getting started
    • Flow dictionary
  5. Fotoware On-Premises
    • Getting started
    • Index Manager
    • FotoWeb
    • Color Factory
    • Connect
    • Operations Center Guide
  6. Integrations and APIs
    • The Fotoware API
    • Creating integrations using embeddable widgets
    • Authorizing applications using OAuth
    • Auto-tagging
    • FotoWeb Drag and Drop export
    • Integration using webhooks
    • Optimizely and Episerver plugin documentation
    • User Interface Integrations
  7. Fotoware Mobile
    • User guide for Fotoware Mobile for iPhone and Android
    • User guide to FotoWeb for iPad (Legacy)
    • User guide to FotoWeb for iPhone and Android (Legacy)

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Support

Table of Contents

Adding the FotoWeb application to your SAML provider Example: Okta setup Attribute statements Copy endpoint URL and certificate to FotoWeb site settings Setting the Logout URL Enforcing the use of SAML for login
  • Home
  • Fotoware On-Premises
  • FotoWeb
  • Managing users and groups (On-Premises)
  • Configuring authentication providers and single sign-on in FotoWare (On-Premises)
  • SAML Authentication (On-Premises)

Setting up SAML authentication

30. April 2025

Elaine Foley

Table of Contents

Adding the FotoWeb application to your SAML provider Example: Okta setup Attribute statements Copy endpoint URL and certificate to FotoWeb site settings Setting the Logout URL Enforcing the use of SAML for login

Adding the FotoWeb application to your SAML provider

Example: Okta setup

Okta is an Identity Provider (IdP) which is used as an example to illustrate how to configure FotoWeb to work with an IdP. The procedure may vary slightly depending on the type of IdP being used. 

Create an application in your SAML provider's management console and set the following parameters:

Single sign on URL  (aka Assertion Consumer Service URL or ACS URL)
Use the hostname to your FotoWeb server followed by /fotoweb/auth/saml20/consume/, for example: https://example.fotoware.cloud/fotoweb/auth/saml20/consume/

Important: Remember to include the final forward slash at the end of the URL, as seen above.

Issuer ID / Audience URI: 

In FotoWeb 8.0 build 837 and newer, the Audience URI must match the correct Issuer ID - the site URL - including a final forward slash, as in the following example:

https://example.fotoware.cloud/fotoweb/

Important: Remember to include the final forward slash at the end of the URL, as seen above.

In earlier versions of FotoWeb, the Audience URI must read FotoWeb, as in the screenshot above.

Attribute statements

In the Attribute statements section, map the FotoWeb attributes to those of your SAML provider.

The screenshot below shows the mapping between FotoWeb and Okta, where the FotoWeb attributes are shown in the left column (email, givenName, sn, username) and the correponding Okta values are shown in the right column. 

Note:

  1. The names of the attributes in FotoWeb can be customized, for instance to accommodate IdPs that send a fixed attribute value.
  2. Additional attributes can be added to import more information about users, such as group membership.

Important: Make sure you enter the FotoWeb attributes EXACTLY as specified in the left column. If you've changed the name of the corresponding FotoWeb values in the Operations Center Settings app, enter them accordingly here. The values must match, otherwise users will not be able to authenticate and log in.

Copy endpoint URL and certificate to FotoWeb site settings

After setting up the application, the SAML provider will give you an endpoint URL to which FotoWeb will send authentication queries, along with an X.509 certificate. These must be copied into the SAML authentication settings in the FotoWeb site configuration in the Operations Center Settings app, as shown below.

Setting the Logout URL

The Logout URL can be obtained from the IdP.

If the user logs out from FotoWeb, or the session is terminated by other means, the user will be redirected to the custom logout URL.

The custom logout URL may be a "start page" with links to FotoWeb and other applications to which the user can log in via SAML. For example, services such as Okta, Google GSuite and ADFS can have such pages. When using sign-in initiated by the identity provider (where the user signs in to FotoWeb from an external page, rather than the FotoWeb login page), this provides a more natural experience, where the user returns to the "start page" after leaving FotoWeb.

The custom logout URL is used regardless if the FotoWeb login page is enabled or not ("always log in with SSO"). This may be useful in cases where most users are expected to log in via SSO, but a select few (typically administrators) log in via the FotoWeb login form.

If no custom logout URL is specified, and the FotoWeb login page is disabled ("always log in with SSO"), then the user is taken to a default page after logout, which has a link to log back in via SSO.

The custom logout page may also be a link that logs the user out of the session in the identity provider. However, it is not an implementation of SAML single sign-out.

Enforcing the use of SAML for login

By selecting the Only allow login with SAML option, users who access FotoWeb are not given the opportunity to manually enter a username and password to authenticate but are immediately authenticated using SAML when accessing the FotoWeb site. By leaving the Only allow login with SAML option unchecked, it will be possible to enter a FotoWeb username and password manually to log in. To log in with SSO then, you need to select Login with SSO from the login screen as you cannot manually enter your SAML credentials to log in.

saml setup authentication

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Installing FotoWeb
  • Activating a Fotoware license with a license server
  • FAQ: Licensing and product activation
eco-lighthouse-miljøfyrtårn

Company

  • About us
  • Resellers
  • Careers
  • Contact us

Help & support

  • Support center
  • Consultancy
  • Tech partners
  • Fotostation
  • System status

Trust Center

  • Legal
  • Security
  • Sustainability & ESG

Locations

Fotoware AS (HQ)
Tollbugata 35
0157 OSLO
Norway
FotoWare Switzerland AG
Industriestrasse 25
5033 Buchs (AG)
Switzerland

Copyright 2025 Fotoware All rights reserved.

  • Terms of service
  • Privacy policy
  • Cookie policy

Knowledge Base Software powered by Helpjuice

Expand