Why are SAML Configurations too Limited for our Upgraded Business Tier Account?

Ok, so there’s no metadata url unfortunately (our SAML provider is Google).

It seems like the recommended workaround is to download the SAML metadata file, and then put it somewhere where Pipedream could download it via a temporary public URL… :grimacing:

Obviously, to download the metadata file from Google, we need to be authenticated.

Not the most straightforward setup, compared to copy-pasting the values (or even just uploading the metadata file directly).

I see thanks, let me look into this more and bring it back to the team.

We’ll try to host the file somewhere in the meantime.

: Once the SAML setup is done, we can delete the file, right?

No need to leave it on a public url permanently?

before you do, let me look into it more

I am not sure

some information on this here: Security concerns with providing SAML metadata on public URL - Stack Overflow

SAML still depends on private data shared between Pipedream + your provider, this just communicates public information. If you want to wait and enter the data manually, I’m discussing that with the team and can keep you updated

We can do the file. Biggest question is whether or not the file/url needs to remain there permanently, or just be used once.

: Also, did you want to create the Slack Connect channel, or should we?

We can do the file. Biggest question is whether or not the file/url needs to remain there permanently, or just be used once. (edited)
I looked at the code and we do need it moving forward for SSO to work

I’ll create the Slack channel right now

just invited you

Got it!

Just waiting for admin approval… might not happen until tomorrow.

Also of note: Google OAuth SSO doesn’t really seem to change anything:

image.png

I can still invite anyone:

image.png

And they can accept the invite and login into the workspace:

image.png

yes, we need to do work to actually enforce SSO-only logins, which it sounds like you want to do?