Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • All tutorials
    • Differentiation of access permissions for user groups
    • Service account with an OS Login profile for VM management via Ansible
      • Overview
      • 1C:Enterprise
      • Grafana OSS
      • Harbor
        • SAML
        • OpenID Connect
      • Managed Service for GitLab
      • Managed Service for OpenSearch
      • MWS
      • NetBird
      • OpenSearch
      • Selectel
      • Sentry
      • SonarQube
      • VK Cloud
      • Zabbix
      • Passwork
      • Yandex 360
      • Yandex Browser for organizations
      • Using OAuth2 Proxy for applications not supporting SSO
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes
  • Yandex Identity Hub Sync Agent release notes

In this article:

  • Generate a key and certificate
  • Create an app
  • Set up the integration
  • Configure endpoints and upload the service provider certificate
  • Configure user attributes
  • Set up SAML authentication in Loop
  • Add users
  • Make sure your application works correctly
  1. Tutorials
  2. Setting up single sign-on (SSO) for apps
  3. Loop
  4. SAML

Creating a SAML app in Yandex Identity Hub for integration with Loop

Written by
Yandex Cloud
Updated at September 1, 2026
View in Markdown
  • Generate a key and certificate
  • Create an app
  • Set up the integration
    • Configure endpoints and upload the service provider certificate
    • Configure user attributes
    • Set up SAML authentication in Loop
  • Add users
  • Make sure your application works correctly

Loop is a corporate messenger with single sign-on support based on the SAML standard.

For the users of your organization to be able to authenticate to Loop via SAML SSO, create a SAML app in Yandex Identity Hub and configure it both in Yandex Identity Hub and Loop.

SAML apps can be managed by users with the organization-manager.samlApplications.admin role or higher.

To give access to Loop to the users of your organization:

  1. Generate a key and certificate.
  2. Create an app.
  3. Set up the integration.
  4. Add users.
  5. Make sure the application works correctly.

Generate a key and certificateGenerate a key and certificate

To encrypt and sign SAML responses, Loop requires a service provider (SP) certificate and private key. To generate it, use openssl:

openssl req -x509 -newkey rsa:2048 \
  -keyout private.key \
  -out certificate.crt \
  -days 365 -nodes \
  -subj "/CN=<instance_name>.loop.ru"

Where <instance_name> is your Loop instance name (subdomain on loop.ru).

This command will create two files, private.key and certificate.crt. Save them, as you will need them to configure SAML in Loop.

Create an appCreate an app

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select  Apps.
  3. Click Create application and in the window that opens:
    1. Select the SAML (Security Assertion Markup Language) single sign-on method.
    2. In the Name field, specify a name for your new app: loop-saml-app.
    3. Optionally, add a description and labels for the app.
    4. Click Create application.
  4. On the Overview tab, under Application certificate, click Download certificate and save the new app’s certificate, loop-saml-app.cer; you will need it to configure SAML in Loop.

Set up the integrationSet up the integration

To configure Loop integration with the SAML app you created in Yandex Identity Hub, complete the configuration on both the Yandex Identity Hub side and in Loop.

Configure endpoints and upload the service provider certificateConfigure endpoints and upload the service provider certificate

Specify the details of your Loop instance. To find out endpoint values, go to the Loop system console at https://<instance_name>.loop.ru/admin_console/authentication/saml and copy the Entity ID and ACS URL values from the SAML settings.

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, click Apps and select loop-saml-app.
  3. At the top right, click Edit and in the window that opens:
    1. Under Service provider (SP) configuration:
      1. In the **SP EntityID ** field, enter Entity ID, the unique service provider ID.

      2. In the ACS URL field, enter ACS URL, the address to which the service provider will send requests for user authentication.

      3. Optionally, add more ACS URL addresses by pressing Add URL.

      4. Optionally, in the SP Logout URL field, add the address to which the IdP will send the SAML response after the user successfully logs out.

      5. In the Signature mode field, select which parts of the SAML response will be signed:

        • Assertions: Sign only user data payloads (ID, attributes, and authentication timestamp).
        • Response: Sign the entire SAML response.
        • Assertions and Response: Sign both the user payloads and the entire response.
    2. Optionally, to only accept requests signed by one of the added certificates, enable Only accept signed requests and add the certificate by clicking Add certificate.
    3. To ensure SAML response encryption using the selected certificate, enable Encrypt assertion in response and add the previously created certificate by clicking Add certificate.
    4. From the Data encryption algorithm list, select RSA-OAEP-SHA256 (recommended).
    5. From the Key encryption algorithm list, select RSA-OAEP-SHA1.
    6. Click Save.

Configure user attributesConfigure user attributes

Cloud Center UI
  1. Log in to Yandex Identity Hub.

  2. In the left-hand panel, click Apps and select loop-saml-app.

  3. Navigate to the Attributes tab.

  4. Add an attribute for providing the username. At the top right, click Add attribute and in the window that opens:

    • In the Attribute name field, enter username.
    • In the Value field, select SubjectClaims.preferred_username.

    Note

    Use transformations to change the attribute value before sending it to the application, e.g., to convert text to lower case, remove spaces, or extract part of the row. Transformations apply one by one, from top to bottom.

    • Click Add transformation, and select the ExtractBefore transformation type. In the Substring field, enter @. This will extract the part of email address up to the @ symbol to serve as the username in the Loop.
    • Click Add.

Set up SAML authentication in LoopSet up SAML authentication in Loop

  1. Log in to the Loop system console at https://<instance_name>.loop.ru/admin_console/authentication/saml.
  2. Under Authentication:
    1. Activate the Enable SAML 2.0 login option.

    2. In the IdP metadata URL field, enter the address to which Loop sends its metadata request.

      How to find out the address of the app metadata file
      1. Log in to Yandex Identity Hub.
      2. In the left-hand panel, navigate to Apps and select loop-saml-app.
      3. Under Identity provider (IdP) configuration, copy the Metadata URL field value.
    3. In the SAML SSO URL field, enter the address to which Loop sends the SAML request to initiate the login flow.

      How to find out the authentication request address
      1. Log in to Yandex Identity Hub.
      2. In the left-hand panel, navigate to Apps and select loop-saml-app.
      3. Under Identity provider (IdP) configuration, copy the Login URL field value.
    4. In the IdP issuer URL field, enter the address used for SAML requests.

      How to find out the IdP issuer URL
      1. Log in to Yandex Identity Hub.
      2. In the left-hand panel, navigate to Apps and select loop-saml-app.
      3. Under Identity provider (IdP) configuration, copy the Issuer / IdP EntityID field value.
    5. Under CA public certificate, upload the loop-saml-app.cer certificate file.

    6. Enable Signature verification.

    7. In the Service provider sign-in URL field, enter https://<instance_name>.loop.ru/login/sso/saml. Also specify this address in the Service provider ID field.

    8. Activate the Enable encryption option.

    9. Under Service provider private key, upload the private.key file.

    10. Under Service provider public certificate, upload the certificate.crt file.

    11. In the Signature algorithm list, select the RSAwithSHA512 request signature algorithm.

    12. In the Canonicalization algorithm list, select Exclusive XML Canonicalization 1.0 (skip comments).

    13. In the Email attribute field, specify emailaddress.

    14. In the Username attribute field, specify username.

    15. Optionally, in the Name attribute field, specify the givenname attribute to populate the user’s first name in Loop.

    16. Optionally, in the Last name attribute field, specify the surname attribute to populate the user’s last name in Loop.

    17. Optionally, in the Login button text field, enter the sign-in button text to display on the login page. The default text is Sign in with SAML.

  3. Click Save.

Add usersAdd users

To enable user authentication in Loop, add the required users and/or user groups to your Yandex Identity Hub SAML application.

Note

Users and groups added to a SAML application can be managed by a user with the organization-manager.samlApplications.userAdmin role or higher.

To add users to a SAML application:

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select Apps and select the required app.
  3. Navigate to the Users and groups tab.
  4. Click Add users.
  5. In the window that opens, select the required users.
  6. Click Add.

Tip

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.

Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.

Make sure your application works correctlyMake sure your application works correctly

To make sure both your SAML app and integration with Loop work correctly, log in to Loop as one of the users you added to the app. Proceed as follows:

  1. In your browser, open the login page of your Loop instance: https://<instance_name>.loop.ru.
  2. Select Sing in with SAML.
  3. Authenticate in Yandex Cloud under a user account from your organization.
  4. Make sure you have signed in to Loop following a successful authentication.

Was the article helpful?

Previous
OpenID Connect
Next
OpenID Connect
© 2026 Direct Cursus Technology L.L.C.