



| Field | Value |
|---|---|
| Client Type | SAML |
| Client ID | https://www.expensify.com |
| Name | Expensify |
| Description | SSO Integration |
| Assertion Consumer Service URL | https://www.expensify.com/saml/acs (or loginCallback pattern) |
NameID Policy Format | Email |
| Field | Value |
|---|---|
| Client Type | SAML |
| Client ID | https://www.expensify.com |
| Name | Expensify |
| Description | SSO Integration |
| Always Display in UI | ON |
| Field | Value |
|---|---|
| Home URL | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/expensify |
| Valid Redirect URIs | https://www.expensify.com/saml/acs (or loginCallback pattern) |
| IDP-Initiated SSO URL Name | expensify |
| Setting | Value |
|---|---|
| Name ID Format | |
| Force Name ID Format | OFF |
| Force POST Binding | ON |
| Include AuthnStatement | ON |
| Setting | Value |
|---|---|
| Sign Documents | OFF |
| Sign Assertions | ON |
| Field | Value |
|---|---|
| Mapper Type | User Attribute |
| Name | |
| User Attribute | |
| Friendly Name | |
| SAML Attribute Name | email |
| Field | Value |
|---|---|
| Mapper Type | User Attribute |
| Name | givenname |
| User Attribute | firstname |
| Friendly Name | givenname |
| SAML Attribute Name | givenname |
| Field | Value |
|---|---|
| Mapper Type | User Attribute |
| Name | surname |
| User Attribute | lastName |
| Friendly Name | surname |
| SAML Attribute Name | surname |