


| Field | Value |
|---|---|
| Entity ID provided by the IdP | https://ca.auth.kzero.com/realms/<TENANT_NAME> |
| SAML SSO URL | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml |
| Signing Options | Only Signed Response |
| Security Certificate | Tenant Certificate available at: https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/descriptor |
| Field | Value |
|---|---|
| NameID Format | urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress |
| Encrypted Assertions | OFF |
| Should AuthnRequests be signed? | ON |
| SAML Signature Method | RSA – SHA 256 (Recommended) |
| SAML Single Logout | OFF |
| SP initiated request binding | HTTP_POST |
| Update profile every time a user logs in | ON |
| Button Label | Multi-Pass SSO |
| Field | Value |
|---|---|
| Client ID (=SP Entity ID) | https://<FW_DOMAIN>.myfreshworks.com/sp/SAML/881543301655492912/metadata |
| Name | freshworks |
| Description | Freshworks SSO integration |
| Assertion Consumer Service URL | https://<FW_DOMAIN>.myfreshworks.com/sp/SAML/881543301655492912/callback |
| NameID Policy Format |
| Field | Value |
|---|---|
| Client ID | https://<FW_DOMAIN>.myfreshworks.com/sp/SAML/881543301655492912/metadata |
| Name | freshworks |
| Description | Freshworks SSO integration |
| Always display in UI | ON |
| Field | Value |
|---|---|
| Home URL (IdP-initiated) | https://ca.auth.kzero.com/<TENANT_NAME>/protocol/saml/clients/<APP_NAME> |
| Valid Redirect URIs (ACS) | https://<FW_DOMAIN>.myfreshworks.com/sp/SAML/881543301655492912/callback |
| IDP-Initiated SSO URL Name | <APP_NAME> |
| Setting | Value |
|---|---|
| Name ID Format | |
| Force Name ID Format | OFF |
| Force POST Binding | ON |
| Include AuthnStatement | ON |
| Setting | Value |
|---|---|
| Sign Documents | ON |
| Sign Assertions | ON |