# SSO using SAML keycloak

**URL:** <https://vaultwarden.discourse.group/t/sso-using-saml-keycloak/2489>\
**Category:** Uncategorized\
**Created:** [March 22, 2023, 4:11am UTC](https://vaultwarden.discourse.group/t/sso-using-saml-keycloak/2489 "2023-03-22T04:11:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![soap](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@soap](https://vaultwarden.discourse.group/u/soap)\
**Post date:** [March 22, 2023, 4:11am UTC](https://vaultwarden.discourse.group/t/sso-using-saml-keycloak/2489/1 "2023-03-22T04:11:30Z")

</div>

Hello All, I’m new here and going try Vaultwarden.

Can I check something? I’m aware that Bitwarden is able to integrate with keycloak. But, for Vaultwarden, is it able to integrate with keycloak too? If not, what are the other alternatives?

---

<div class="post-metadata">

**Author:** ![stefan0xC](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/stefan0xc/32/1765_2.png) [@stefan0xC](https://vaultwarden.discourse.group/u/stefan0xC)\
**Post date:** [March 22, 2023, 6:24am UTC](https://vaultwarden.discourse.group/t/sso-using-saml-keycloak/2489/2 "2023-03-22T06:24:37Z")

</div>

[SSO integration is not implemented](https://github.com/dani-garcia/vaultwarden/wiki#missing-features) yet. There have been a couple of [pull requests](https://github.com/dani-garcia/vaultwarden/pulls) but I don’t know if any of them are ready to be merged or actively worked on.

The only alternative I’m currently aware of is using [a third-party LDAP connector](https://github.com/ViViDboarder/vaultwarden_ldap) to [invite users to vaultwarden](https://github.com/dani-garcia/vaultwarden/wiki/Syncing-users-from-LDAP). If you need SSO you should consider using the self-hosting option of the official Bitwarden server (or maybe try [the new unified beta](https://bitwarden.com/help/install-and-deploy-unified-beta/)?)

---

<div class="post-metadata">

**Author:** ![soap](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@soap](https://vaultwarden.discourse.group/u/soap)\
**Post date:** [March 22, 2023, 9:24am UTC](https://vaultwarden.discourse.group/t/sso-using-saml-keycloak/2489/3 "2023-03-22T09:24:48Z")

</div>

Seems like it only the Bitwarden enterprise license is only capable of doing the SSO. I’m not so sure with the new unified beta? Can provide me more information regards to that?

---

<div class="post-metadata">

**Author:** ![stefan0xC](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/stefan0xc/32/1765_2.png) [@stefan0xC](https://vaultwarden.discourse.group/u/stefan0xC)\
**Post date:** [March 22, 2023, 10:01am UTC](https://vaultwarden.discourse.group/t/sso-using-saml-keycloak/2489/4 "2023-03-22T10:01:23Z")

</div>

Yeah, the enterprise license will probably also be required for SSO in the beta (which is apparently not enabled by default) but I don’t really have more infos regarding this. I suggest you talk to Bitwarden directly or ask in their community forum.

---

<div class="post-metadata">

**Author:** ![Avsynthe](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/avsynthe/32/1055_2.png) [@Avsynthe](https://vaultwarden.discourse.group/u/Avsynthe)\
**Post date:** [April 7, 2023, 3:35am UTC](https://vaultwarden.discourse.group/t/sso-using-saml-keycloak/2489/5 "2023-04-07T03:35:38Z")

</div>

It’s coming along. You can follow the work here:

> <https://github.com/dani-garcia/vaultwarden/pull/3154>
>
> Based off previous work by @pinpox and @m4w0lf
> https://github.com/dani-garcia/v…aultwarden/pull/2787
> https://github.com/dani-garcia/vaultwarden/pull/2449
> 
> All config is now done in the environment variables, removed all unneeded calls. 
> Bitwarden removed the identify payload from the client so the first organization is always used when using a domain\_hint
> 
> Currently Working:
> \- Login from all web clients using sso
> \- Creating MasterPassword on new SSO Login when no user exists.
> 
> Not Working:
> \- Joining Organization link never fires accept so user never accepts invite during SSO login, normal login after the first SSO login that creates the account works
> \*The above has a workaround that can be enabled to accept all invites on login\*
> 
> How to test:
> Add the following environment variables and have at least one organization created in your instance
> 
> \`
> SSO\_ENABLED: "true"
> 
> SSO\_CLIENT\_ID: "111111111111111111111111111111111"
> 
> SSO\_CLIENT\_SECRET: "222222222222222222222222222222222222222222222"
> 
> SSO\_AUTHORITY: "https://auth.example.com"
> 
> //Optional
> SSO\_ACCEPTALL\_INVITES: "true"
> \`
> 
> The callback url currently is always:
> Replace example.com with your vaultwarden domain.
> https://example.com/identity/connect/oidc-signin
