Skip to main content

Setup a SAML Identity Provider Mapper in Keycloak

17/08/2026

You can set up a SAML 2.0 identity provider (IDP) mapper in Keycloak to map Graph Modeling user metadata, groups and roles. You need this mapper to match Graph Modeling metadata (such as user name and email address) and information related to authorization (groups and roles) with corresponding user attributes that the SAML IDP provides.

Note

Mapping givenname to firstname

The IDP used by your organization may store first names under the attribute givenname. Graph Modeling stores the first name in the attribute firstname.

To set up a SAML IDP mapper in Keycloak, refer to the Keycloak documentation.

Note

The choice and configuration of the Mapper Type depend on the assertions coming from your IDP. For more information, refer to the Keycloak documentation.

You can choose the Mapper Type and configure the corresponding mapping. Graph Modeling has the following attributes which you can map in Keycloak:

Table 1. Graph Modeling Attributes for Keycloak

PoolParty Attribute

Keycloak Identity Provider Mapper Type

Comment

firstName

Attribute Importer, Hard-coded Attribute

lastName

Attribute Importer, Hard-coded Attribute

email

Attribute Importer, Hard-coded Attribute

username

Attribute Importer, Hard-coded Attribute, Username Template Importer

Usernames must be unique.

roles

SAML Attribute to Role/Advanced Attribute to Role/Hard-coded Role

Configure three separate SAML mappers—one for each client (ppt, ppgs, extractor). For example ppt-PoolPartyUser, ppgs-PoolPartyUser and extractor-PoolPartyUser.

groups

SAML Attribute to Group

Use one of the special role mappers and select one of the PoolParty groups as target.