Skip to main content
B2B & Multi-tenant

Let your customers set up their own SSO. No support tickets required.

A guided, customer-facing wizard that walks each tenant admin through configuring their own SAML or OIDC identity provider — without filing a ticket with you.

SAML 2.0OIDCAuto-DiscoveryClaim MappingEmbeddable
IdP Wizard · architecture
The problem

SSO configuration is one of the biggest support burdens in B2B.

Pain 1

Every customer wants their IdP

Okta, Azure, Google, Ping, custom SAML — every enterprise customer brings their own. Setting each one up is bespoke work.

Pain 2

Configuration trips up admins

Entity IDs, ACS URLs, claim mapping, signing certs — most customer admins have never seen these before and end up emailing you screenshots.

Pain 3

Your team becomes their helpdesk

Without a self-serve flow, SSO setup means a back-and-forth that can take days. You can't ship faster than your support backlog.

Our approach

Configuration that looks like a product, not a config file

We turned SSO setup into a guided UI that the customer admin uses inside your app.

01

Pick the IdP, not the protocol

Customer picks 'Okta' or 'Azure' — we generate the right SAML or OIDC config under the hood.

02

Auto-discover everything we can

Metadata URLs, tenant IDs, claim names — we pull what's discoverable, only ask for the rest.

03

Test before you save

Built-in test login so customers know it works before going live.

04

Embed it anywhere

Drop the wizard into your own admin UI. Or use it standalone.

What teams use it for

Where self-serve SSO pays off

Whenever an enterprise customer needs SSO and your team doesn't want to be in the middle of it.

01
Enterprise tier onboarding
Self-serve the highest-value step.
02
Trial → paid upgrade
Customer flips on SSO themselves.
03
Multi-product orgs
Same wizard configures SSO across all products.
04
White-label SaaS
Embed in your customer's branded admin UI.
Key capabilities

Walkthrough setup, production-grade plumbing

Okta / Azure / Google quick-start

Pre-built recipes for the most common enterprise IdPs.

Generic SAML & OIDC

Fall back to a guided generic flow for anything else.

Metadata auto-import

Paste a URL, we fetch the SAML metadata for them.

Claim mapping UI

Map IdP claims to Keycloak attributes without editing XML.

Test login flow

Verify the connection works before exposing it to end users.

Embed via iframe or SDK

Drop the wizard into your own admin surface.

Get started

Three ways to ship IdP Wizard

Self-host

Run it yourself

Pull the JAR or pre-built container into your Keycloak deployment.

Docs

Read the guides

Install steps, configuration, API reference, and migration notes.

Hosted

Let us run it

Try the hosted Phase Two — all extensions installed and configured.

Ready to Try Keycloak?
Create Your Free Deployment Today.