Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • All tutorials
    • Differentiation of access permissions for user groups
    • Service account with an OS Login profile for VM management via Ansible
      • Overview
      • 1C:Enterprise
      • Grafana OSS
      • Harbor
        • SAML
        • OpenID Connect
      • Managed Service for GitLab
      • Managed Service for OpenSearch
      • MWS
      • NetBird
      • OpenSearch
      • Open WebUI
      • Selectel
      • Sentry
      • SonarQube
      • VK Cloud
      • Zabbix
      • Passwork
      • Yandex 360
      • Yandex Browser for organizations
      • Using OAuth2 Proxy for applications not supporting SSO
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes
  • Yandex Identity Hub Sync Agent release notes

In this article:

  • Create an app in Yandex Identity Hub
  • Set up the integration
  • Set up the SAML application in Yandex Identity Hub
  • Set up authentication in LibreChat
  • Add a user
  • Make sure your application works correctly
  1. Tutorials
  2. Setting up single sign-on (SSO) for apps
  3. LibreChat
  4. SAML

Creating a SAML app in Yandex Identity Hub for integration with LibreChat

Written by
Yandex Cloud
Updated at September 25, 2026
View in Markdown
  • Create an app in Yandex Identity Hub
  • Set up the integration
    • Set up the SAML application in Yandex Identity Hub
    • Set up authentication in LibreChat
    • Add a user
  • Make sure your application works correctly

LibreChat is a free open-source platform that provides an easy way to work with large language models, AI agents, and MCP servers and can be deployed in your own infrastructure. LibreChat supports the SAML standard to provide secure SSO for your organization's users.

For the users of your organization to be able to authenticate to LibreChat via SAML SSO, create a SAML app in Yandex Identity Hub and configure it both in Yandex Identity Hub and LibreChat.

SAML apps can be managed by users with the organization-manager.samlApplications.admin role or higher.

Note

For successful SAML integration, configure access to your LibreChat instance over https using a valid TLS certificate.

To provide your organization's users with access to LibreChat:

  1. Create an app in Yandex Identity Hub.
  2. Set up the integration.
  3. Make sure the application works correctly.

Create an app in Yandex Identity HubCreate an app in Yandex Identity Hub

Cloud Center UI
  1. Log in to Yandex Identity Hub.

  2. In the left-hand panel, select  Apps.

  3. In the top-right corner, click Create application and in the window that opens:

    1. Select the SAML (Security Assertion Markup Language) single sign-on method.
    2. In the Name field, specify a name for your new app: librechat-saml-app.
    3. Optionally, enter the app description and add labels.
    4. Click Create application.
  4. On the new app page that opens:

    1. Under Identity provider (IdP) configuration, copy and save the Login URL field value for later to configure the integration in LibreChat.

    2. Under Application certificate, click Download certificate to get your SAML app certificate.

      Copy the certificate file you got to the server where you deployed your LibreChat instance.

Set up the integrationSet up the integration

To configure LibreChat integration with the SAML app you created, complete the configuration both on the Yandex Identity Hub side and in LibreChat.

Set up the SAML application in Yandex Identity HubSet up the SAML application in Yandex Identity Hub

Cloud Center UI
  1. Log in to Yandex Identity Hub.

  2. In the left-hand panel, select Apps and then, the SAML app.

  3. Set up service provider endpoints. To do this, at the top right, click Edit and in the window that opens:

    1. In the **SP EntityID ** field, specify any value, e.g., your LibreChat instance address: https://librechat.example.com.
    2. In the ACS URL field, enter this address: https://<LibreChat_instance_address>/oauth/saml/callback.
    3. Click Save.
  4. Configure mapping for the username attribute which will be used as the username when authenticating to LibreChat. Follow these steps:

    1. Navigate to the Attributes tab.

    2. In the top-right corner, click Add attribute and in the window that opens:

      1. In the Attribute name field, enter username.
      2. In the Value field, select SubjectClaims.preferred_username.
      3. Click Add.

    For more information about configuring attributes, see Configure user and group attributes.

Set up authentication in LibreChatSet up authentication in LibreChat

On the host running your LibreChat instance, set the following environment variables in the instance runtime environment to configure the LibreChat integration with the SAML application:

Variable name Value
SAML_ENTRY_POINT Login URL value you saved previously.
SAML_ISSUER SP EntityID value you set previously on the Yandex Identity Hub side.

Here is an example: https://librechat.example.com.
SAML_CERT Local path to the SAML app certificate file in the runtime of your LibreChat instance, which you saved earlier.

Here is an example: "/app/saml-certs/librechat-saml-app.cer".
SAML_CALLBACK_URL "https://<LibreChat_instance_address>/oauth/saml/callback"
SAML_SESSION_SECRET Additional secret for session security.

Generate a strong secret of at least 32 characters.
SAML_EMAIL_CLAIM "emailaddress"
SAML_USERNAME_CLAIM "username"
SAML_GIVEN_NAME_CLAIM "givenname"
SAML_FAMILY_NAME_CLAIM "surname"
SAML_NAME_CLAIM "fullname"
SAML_BUTTON_LABEL "Login with Yandex Identity Hub"

Add a userAdd a user

For your organization's users to be able to authenticate to LibreChat with Yandex Identity Hub SAML app, explicitly add these users and/or user groups to the SAML application:

Note

Users and groups added to a SAML application can be managed by a user with the organization-manager.samlApplications.userAdmin role or higher.

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select Apps and select the required app.
  3. Navigate to the Users and groups tab.
  4. Click Add users.
  5. In the window that opens, select the required user or user group.
  6. Click Add.

Tip

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.

Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.

Make sure your application works correctlyMake sure your application works correctly

To make sure both your SAML app and LibreChat integration work correctly, authenticate to LibreChat as one of the users you added to the app. Follow these steps:

  1. In your browser, open the LibreChat instance login page.
  2. Select login via Yandex Identity Hub.
  3. Authenticate in Yandex Cloud as your organization’s user you added to the SAML app.
  4. Make sure you have successfully authenticated to LibreChat.

Was the article helpful?

Previous
OpenID Connect
Next
OpenID Connect
© 2026 Direct Cursus Technology L.L.C.