


Admins can enable SAML single sign-on only for end users, only for team members (including light agents and contributors), or for both groups. You can create multiple SAML SSO configurations. Before you start, obtain the required information from your company's IT team.| Field | Value |
|---|---|
| Configuration Name | e.g. Multi-Pass |
| SAML SSO URL | https://ca.auth.kzero.com/realms/<REALM_NAME>/protocol/saml |
| Certificate Fingerprint | From Multi-Pass certificate (see below how to find the certificate) |
| Field | Value |
|---|---|
| Client ID | https://kelvinzero.zendesk.com/ |
| Name | zendesk |
| Description | Test SSO |
Assertion Consumer Service URL | |
| NameID Policy Format | email |
| Field | Value |
|---|---|
| Client ID | https://<YOUR_SUBDOMAIN>.zendesk.com |
| Name | e.g. zendesk |
| Description | e.g. Test SSO |
| Always Display in UI | ON |
| Field | Value |
|---|---|
| Home URL | https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_Name> |
| Valid Redirect URIs | https://<YOUR_SUBDOMAIN>.zendesk.com/access/saml/ |
| IDP-Initiated SSO URL Name | <APP_Name> (e.g. zendesk) |
| Setting | Value |
|---|---|
| Name ID Format | |
| Force POST Binding | ON |
| Include AuthnStatement | ON |
| Include AuthnStatement | ON |
| Field | Value |
|---|---|
| Assertion Consumer Service POST Binding URL | Same as Valid Redirect URI (https://<SUBDOMAIN>.zendesk.com/access/saml/) |