# \#saml

**URL:** https://meta.discourse.org/tag/saml/291.md

[Latest](https://meta.discourse.org/latest.md) · [Categories](https://meta.discourse.org/categories.md) · [Tags](https://meta.discourse.org/tags.md)

---

## [CSRFTokenVerifier::InvalidCSRFToken when initiating SAML login on Discourse 2026.6](https://meta.discourse.org/t/csrftokenverifier-invalidcsrftoken-when-initiating-saml-login-on-discourse-2026-6/406986)

<div class="topic-metadata">

**Author:** [@Osman\_Nuri\_Mermer](https://meta.discourse.org/u/Osman_Nuri_Mermer)\
**Replies:** 0\
**Last updated:** [July 7, 2026, 2:57pm UTC](https://meta.discourse.org/t/csrftokenverifier-invalidcsrftoken-when-initiating-saml-login-on-discourse-2026-6/406986 "2026-07-07T14:57:12Z")

</div>

CSRFTokenVerifier::InvalidCSRFToken when initiating SAML login on Discourse 2026.6 Hi, I’m trying to configure SAML authentication with ADFS on a fresh Discourse installation. Environment Discourse version: 2026.6 (R…

---

## [SAML logout stops working](https://meta.discourse.org/t/saml-logout-stops-working/369703)

<div class="topic-metadata">

**Author:** [@dojo](https://meta.discourse.org/u/dojo)\
**Replies:** 3\
**Last updated:** [September 16, 2025, 2:16pm UTC](https://meta.discourse.org/t/saml-logout-stops-working/369703 "2025-09-16T14:16:17Z")

</div>

I’m using the SAML-Plugin to connect to a keycloak instance. Since the last update the logout is not working. I just get a Not Implemented on the /auth/saml/spslo site when clicking ‘Logout’. When going back in browsers…

---

## [Create Plugin to Logout user via uid from SAML](https://meta.discourse.org/t/create-plugin-to-logout-user-via-uid-from-saml/377116)

<div class="topic-metadata">

**Author:** [@PortChange](https://meta.discourse.org/u/PortChange)\
**Replies:** 0\
**Last updated:** [August 4, 2025, 12:11am UTC](https://meta.discourse.org/t/create-plugin-to-logout-user-via-uid-from-saml/377116 "2025-08-04T00:11:19Z")

</div>

I use SAML groups to authenticate users to different categories. When the groups change, the user has to login. I want to automate this in my IDP. When groups changes, it uses the API to logout user curl -X POST “https:…

---

## [Using Assertion Lifespan to update SAML Groups on a regular basis](https://meta.discourse.org/t/using-assertion-lifespan-to-update-saml-groups-on-a-regular-basis/367227)

<div class="topic-metadata">

**Author:** [@BaoLe](https://meta.discourse.org/u/BaoLe)\
**Replies:** 0\
**Last updated:** [May 22, 2025, 1:50pm UTC](https://meta.discourse.org/t/using-assertion-lifespan-to-update-saml-groups-on-a-regular-basis/367227 "2025-05-22T13:50:57Z")

</div>

Hi everyone, i was trying to automatically update the Group Assignments if they change on the IDP side. Unfortunately it only works if the User logs out and on again as the assertions are only transmitted during a login…

---

## [Usernames are deleted on login](https://meta.discourse.org/t/usernames-are-deleted-on-login/359378)

<div class="topic-metadata">

**Author:** [@justintime](https://meta.discourse.org/u/justintime)\
**Replies:** 3\
**Last updated:** [April 1, 2025, 7:25pm UTC](https://meta.discourse.org/t/usernames-are-deleted-on-login/359378 "2025-04-01T19:25:13Z")

</div>

Every time someone clears their cache and re-logins into Discourse, it wipes out their username and resets it to the word “user” and then a number. If I fix the username manually, on the next log back in, the username is…

---

## [Does Discourse Support Just-in-Time (JIT) Provisioning via SAML?](https://meta.discourse.org/t/does-discourse-support-just-in-time-jit-provisioning-via-saml/345380)

<div class="topic-metadata">

**Author:** [@LOKESH\_KUMAR](https://meta.discourse.org/u/LOKESH_KUMAR)\
**Replies:** 0\
**Last updated:** [January 3, 2025, 5:26am UTC](https://meta.discourse.org/t/does-discourse-support-just-in-time-jit-provisioning-via-saml/345380 "2025-01-03T05:26:16Z")

</div>

I would like to know if Discourse supports Just-in-Time (JIT) provisioning for user accounts via SAML. Specifically, can new user accounts be automatically created in Discourse when a user successfully authenticates thro…

---

## [SAML plugin and non standard configuration](https://meta.discourse.org/t/saml-plugin-and-non-standard-configuration/328629)

<div class="topic-metadata">

**Author:** [@Dubravko\_Penezic](https://meta.discourse.org/u/Dubravko_Penezic)\
**Replies:** 0\
**Last updated:** [September 30, 2024, 7:17am UTC](https://meta.discourse.org/t/saml-plugin-and-non-standard-configuration/328629 "2024-09-30T07:17:31Z")

</div>

Hi, does anyone have experience with self-hosted Discourse and SAML plugin with non-standard configuration? I would like to configure parameters to use existing SAML attributes (completely different than the SAML plugi…

---

## [I dont get proper mapping of attributes using SAML plugin](https://meta.discourse.org/t/i-dont-get-proper-mapping-of-attributes-using-saml-plugin/194312)

<div class="topic-metadata">

**Author:** [@JoreisPy](https://meta.discourse.org/u/JoreisPy)\
**Replies:** 6\
**Last updated:** [September 29, 2024, 5:45pm UTC](https://meta.discourse.org/t/i-dont-get-proper-mapping-of-attributes-using-saml-plugin/194312 "2024-09-29T17:45:14Z")

</div>

Hello, I am trying to integrate our shibboleth with our discourse instance. For now logging in works but I am getting the wrong data (name, email, etc…) here is part of the data coming from the SSO \<saml2:Attribut…

---

## [SAML Auth Stuck on Callback phase initiated](https://meta.discourse.org/t/saml-auth-stuck-on-callback-phase-initiated/283324)

<div class="topic-metadata">

**Author:** [@Tchesley](https://meta.discourse.org/u/Tchesley)\
**Replies:** 1\
**Last updated:** [September 28, 2024, 8:07pm UTC](https://meta.discourse.org/t/saml-auth-stuck-on-callback-phase-initiated/283324 "2024-09-28T20:07:01Z")

</div>

Hi All, I’m trying to set up the discourse-saml plugin on my MacOS Dev installation but I believe that something is being missed once I got stuck on (small) Callback phase initiated and nothing happens after that. I ca…

---

## [Discourse SAML plugin - How do I map to the "Web Site" profile field?](https://meta.discourse.org/t/discourse-saml-plugin-how-do-i-map-to-the-web-site-profile-field/279948)

<div class="topic-metadata">

**Author:** [@Jeff\_Gilmore](https://meta.discourse.org/u/Jeff_Gilmore)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:25am UTC](https://meta.discourse.org/t/discourse-saml-plugin-how-do-i-map-to-the-web-site-profile-field/279948 "2023-09-25T01:25:49Z")

</div>

I am using the Discourse SAML plugin and I can’t seem to get a mapping to the built-in profile field “Location”. My identity provider is sending it over: \<saml:Attribute Name="website" …
