


| Field | Value |
|---|---|
| SP Entity ID / Audience / Client ID | https://app.intercom.com/saml/<SAML Name> |
| ACS / Assertion Consumer Service URL | https://app.intercom.com/saml/<SAML Name>/consume |
| NameID Policy Format | |
| Name | intercom |
| Description | SSO integration for Intercom |
| Setting | Value |
|---|---|
| Client ID | https://app.intercom.com/saml/<SAML Name> |
| Name | intercom |
| Description | SSO integration |
| Always display in UI | ON |
| Setting | Value |
|---|---|
| Home URL | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME> |
| Valid Redirect URIs | https://app.intercom.com/saml/<SAML Name>/consume |
| IDP-Initiated SSO URL name | <APP_NAME> |
| Setting | Value |
|---|---|
| Name ID format | |
| Force Name ID format | OFF |
| Force POST binding | ON |
| Include AuthnStatement | ON |
| Setting | Value |
|---|---|
| Sign documents | OFF |
| Sign assertions | ON |
| Field | Value |
|---|---|
| Single Sign‑On URL | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml |
| X.509 Certificate | Paste PEM-formatted cert from MPAS |
| Allowed Domains | example.com, mycompany.org |