Creating a SAML app in Yandex Identity Hub for integration with LibreChat
LibreChat
For the users of your organization to be able to authenticate to LibreChat via SAML
SAML apps can be managed by users with the organization-manager.samlApplications.admin role or higher.
Note
For successful SAML integration, configure access to your LibreChat instance over https using a valid TLS certificate.
To provide your organization's users with access to LibreChat:
- Create an app in Yandex Identity Hub.
- Set up the integration.
- Make sure the application works correctly.
Create an app in Yandex Identity Hub
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, select
Apps. -
In the top-right corner, click
Create application and in the window that opens:- Select the SAML (Security Assertion Markup Language) single sign-on method.
- In the Name field, specify a name for your new app:
librechat-saml-app. - Optionally, enter the app description and add labels.
- Click Create application.
-
On the new app page that opens:
-
Under Identity provider (IdP) configuration, copy and save the Login URL field value for later to configure the integration in LibreChat.
-
Under Application certificate, click Download certificate to get your SAML app certificate.
Copy the certificate file you got to the server where you deployed your LibreChat instance.
-
Set up the integration
To configure LibreChat integration with the SAML app you created, complete the configuration both on the Yandex Identity Hub side and in LibreChat.
Set up the SAML application in Yandex Identity Hub
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, select
Apps and then, the SAML app. -
Set up service provider endpoints. To do this, at the top right, click
Edit and in the window that opens:- In the **SP EntityID ** field, specify any value, e.g., your LibreChat instance address:
https://librechat.example.com. - In the ACS URL field, enter this address:
https://<LibreChat_instance_address>/oauth/saml/callback. - Click Save.
- In the **SP EntityID ** field, specify any value, e.g., your LibreChat instance address:
-
Configure mapping for the
usernameattribute which will be used as the username when authenticating to LibreChat. Follow these steps:-
Navigate to the Attributes tab.
-
In the top-right corner, click
Add attribute and in the window that opens:- In the Attribute name field, enter
username. - In the Value field, select
SubjectClaims.preferred_username. - Click Add.
- In the Attribute name field, enter
For more information about configuring attributes, see Configure user and group attributes.
-
Set up authentication in LibreChat
On the host running your LibreChat instance, set the following environment variables in the instance runtime environment to configure the LibreChat integration with the SAML application:
| Variable name | Value |
|---|---|
SAML_ENTRY_POINT |
Login URL value you saved previously. |
SAML_ISSUER |
SP EntityID value you set previously on the Yandex Identity Hub side.Here is an example: https://librechat.example.com. |
SAML_CERT |
Local path to the SAML app certificate file in the runtime of your LibreChat instance, which you saved earlier.Here is an example: "/app/saml-certs/librechat-saml-app.cer". |
SAML_CALLBACK_URL |
"https://<LibreChat_instance_address>/oauth/saml/callback" |
SAML_SESSION_SECRET |
Additional secret for session security.Generate a strong secret of at least 32 characters. |
SAML_EMAIL_CLAIM |
"emailaddress" |
SAML_USERNAME_CLAIM |
"username" |
SAML_GIVEN_NAME_CLAIM |
"givenname" |
SAML_FAMILY_NAME_CLAIM |
"surname" |
SAML_NAME_CLAIM |
"fullname" |
SAML_BUTTON_LABEL |
"Login with Yandex Identity Hub" |
Add a user
For your organization's users to be able to authenticate to LibreChat with Yandex Identity Hub SAML app, explicitly add these users and/or user groups to the SAML application:
Note
Users and groups added to a SAML application can be managed by a user with the organization-manager.samlApplications.userAdmin role or higher.
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps and select the required app. - Navigate to the Users and groups tab.
- Click
Add users. - In the window that opens, select the required user or user group.
- Click Add.
Tip
If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.
Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.
Make sure your application works correctly
To make sure both your SAML app and LibreChat integration work correctly, authenticate to LibreChat as one of the users you added to the app. Follow these steps:
- In your browser, open the LibreChat instance login page.
- Select login via Yandex Identity Hub.
- Authenticate in Yandex Cloud as your organization’s user you added to the SAML app.
- Make sure you have successfully authenticated to LibreChat.