


| Field | Value |
|---|---|
| Issuer | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/descriptor |
| Single Sign On (SSO) URL | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml |
| X.509 Certificate | Open the SAML metadata descriptor at:https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/descriptorLocate the <ds:X509Certificate> tag and copy the certificate contents into the Pipedrive X.509 Certificate field:
-----BEGIN CERTIFICATE----- [Paste the certificate from the XML] -----END CERTIFICATE----- |
| Field | Value |
|---|---|
| Client ID (=SP Entity ID) | https://<PIPEDRIVE_SUBDOMAIN>.pipedrive.com/sso/auth/samlp/metadata.xml |
| Name | pipedrive |
| Description | Pipedrive SSO integration |
| Assertion Consumer Service URL | https://<PIPEDRIVE_SUBDOMAIN>.pipedrive.com/sso/auth/samlp |
| NameID Policy Format | Email |
| Field | Value |
|---|---|
| Client ID | https://<PIPEDRIVE_SUBDOMAIN>.pipedrive.com/sso/auth/samlp/metadata.xml |
| Name | pipedrive |
| Description | Pipedrive SSO integration |
| Always display in UI | ON |
| Field | Value |
|---|---|
| Home URL (IdP-initiated) | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME> |
| Valid Redirect URIs (ACS) | https://<PIPEDRIVE_SUBDOMAIN>.pipedrive.com/sso/auth/samlp |
| IDP-Initiated SSO URL Name | <APP_NAME> |
| Setting | Value |
|---|---|
| Name ID Format | email |
| Force Name ID Format | OFF |
| Force POST Binding | ON |
| Include AuthnStatement | ON |
| Setting | Value |
|---|---|
| Sign Documents | OFF |
| Sign Assertions | ON |
https://<PIPEDRIVE_SUBDOMAIN>.pipedrive.com/sso/auth/samlp