Setup a SAML Identity Provider Mapper in Keycloak
17/08/2026
You can set up a SAML 2.0 identity provider (IDP) mapper in Keycloak to map Graph Modeling user metadata, groups and roles. You need this mapper to match Graph Modeling metadata (such as user name and email address) and information related to authorization (groups and roles) with corresponding user attributes that the SAML IDP provides.
Note
Mapping givenname to firstname
The IDP used by your organization may store first names under the attribute givenname. Graph Modeling stores the first name in the attribute firstname.
To set up a SAML IDP mapper in Keycloak, refer to the Keycloak documentation.
Note
The choice and configuration of the Mapper Type depend on the assertions coming from your IDP. For more information, refer to the Keycloak documentation.
You can choose the Mapper Type and configure the corresponding mapping. Graph Modeling has the following attributes which you can map in Keycloak:
PoolParty Attribute | Keycloak Identity Provider Mapper Type | Comment |
|---|---|---|
firstName | Attribute Importer, Hard-coded Attribute | |
lastName | Attribute Importer, Hard-coded Attribute | |
Attribute Importer, Hard-coded Attribute | ||
username | Attribute Importer, Hard-coded Attribute, Username Template Importer | Usernames must be unique. |
roles | SAML Attribute to Role/Advanced Attribute to Role/Hard-coded Role | Configure three separate SAML mappers—one for each client ( |
groups | SAML Attribute to Group | Use one of the special role mappers and select one of the PoolParty groups as target. |