Configuration Components
Federation in Workbench is defined by the configuration components described below. You should always start in the Staging environment.
For authentication‑only federated sign‑in, all required configuration can be completed by users with the Federation Attributes Edit role.
Component | Who configures | What you configure in Workbench |
|---|---|---|
Allowed Email Domains | Federation Attributes Edit role | The email domains your users sign in with (e.g., company.com). Workbench uses these domains to route users from Sign in with corporate email to your identity provider. Note: Public email domains are not allowed. |
Public Metadata URL | Federation Attributes Edit role | A publicly accessible SAML metadata endpoint from your identity provider. Workbench uses this URL to retrieve your signing certificate, entity ID, and SAML endpoints. The URL must be served over TLS and signed by a public certificate authority. |
Attribute Mapping | Federation Attributes Edit role | The SAML attribute names that map to Workbench user fields: email, first name, and last name. These attributes are used to identify and authenticate users during sign-in. |