1"use strict";(globalThis.webpackChunkbambuser_docs||=[]).push([[4647,5497],{37948(e,n,i){i.r(n),i.d(n,{assets:()=>d,contentTitle:()=>l,default:()=>m,frontMatter:()=>a,metadata:()=>s,toc:()=>c});const s=JSON.parse('{"id":"customSaml","title":"SAML Integration for Custom IAMs","description":"SAML 2.0 SSO between any IdP and the Virtual Commerce dashboard: entity ID bambuser_saml_service_provider, US/EU ACS URLs, claims, group mapping, SCIM.","source":"@site/video-consultation/ssoCustomSaml.mdx","sourceDirName":".","slug":"/sso-custom-saml","permalink":"/docs/video-consultation/sso-custom-saml","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{"id":"customSaml","title":"SAML Integration for Custom IAMs","description":"SAML 2.0 SSO between any IdP and the Virtual Commerce dashboard: entity ID bambuser_saml_service_provider, US/EU ACS URLs, claims, group mapping, SCIM.","sidebar_label":"Custom SAML","slug":"sso-custom-saml"},"sidebar":"someSidebars","previous":{"title":"SAML via Azure","permalink":"/docs/video-consultation/sso-saml-azure"},"next":{"title":"Shopify","permalink":"/docs/video-consultation/shopify-guide"}}');var r=i(74848),t=i(28453),o=i(36818);const a={id:"customSaml",title:"SAML Integration for Custom IAMs",description:"SAML 2.0 SSO between any IdP and the Virtual Commerce dashboard: entity ID bambuser_saml_service_provider, US/EU ACS URLs, claims, group mapping, SCIM.",sidebar_label:"Custom SAML",slug:"sso-custom-saml"},l=void 0,d={},c=[...o.toc];function u(e){return(0,r.jsx)(o.default,{})}function m(e={}){const{wrapper:n}={...(0,t.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(u,{...e})}):u()}},36818(e,n,i){i.r(n),i.d(n,{assets:()=>l,contentTitle:()=>a,default:()=>u,frontMatter:()=>o,metadata:()=>s,toc:()=>d});const s=JSON.parse('{"id":"customSaml","title":"Use a SAML provider","description":"SAML 2.0 SSO setup for the Virtual Commerce dashboard: entity ID bambuser_saml_service_provider, US/EU ACS URLs, claim mapping, X.509, SCIM provisioning.","source":"@site/live/ssoCustomSaml.mdx","sourceDirName":".","slug":"/custom-saml","permalink":"/docs/live/custom-saml","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{"id":"customSaml","title":"Use a SAML provider","description":"SAML 2.0 SSO setup for the Virtual Commerce dashboard: entity ID bambuser_saml_service_provider, US/EU ACS URLs, claim mapping, X.509, SCIM provisioning.","sidebar_label":"Custom SAML","slug":"custom-saml"},"sidebar":"someSidebars","previous":{"title":"SAML via Azure AD","permalink":"/docs/live/saml-azure"},"next":{"title":"Shopify + LiveShopping","permalink":"/docs/live/shopify-guide"}}');var r=i(74848),t=i(28453);i(86025);const o={id:"customSaml",title:"Use a SAML provider",description:"SAML 2.0 SSO setup for the Virtual Commerce dashboard: entity ID bambuser_saml_service_provider, US/EU ACS URLs, claim mapping, X.509, SCIM provisioning.",sidebar_label:"Custom SAML",slug:"custom-saml"},a=void 0,l={},d=[{value:"Overview",id:"overview",level:2},{value:"Step 1: Verify Prerequisites",id:"step-1-verify-prerequisites",level:2},{value:"Step 2: Configure Your Identity Provider",id:"step-2-configure-your-identity-provider",level:2},{value:"Step 3: Share Configuration with Bambuser",id:"step-3-share-configuration-with-bambuser",level:2},{value:"Required Information",id:"required-information",level:3},{value:"Optional Information",id:"optional-information",level:3},{value:"Step 4: Configure User Access",id:"step-4-configure-user-access",level:2},{value:"Option A: Manual User Management (Default)",id:"option-a-manual-user-management-default",level:3},{value:"Option B: Group-based Management (Recommended)",id:"option-b-group-based-management-recommended",level:3},{value:"Step 5: Test and Verify Your Integration",id:"step-5-test-and-verify-your-integration",level:2},{value:"Optional: Automated User Provisioning (SCIM)",id:"optional-automated-user-provisioning-scim",level:2},{value:"Support",id:"support",level:2}];function c(e){const n={a:"a",admonition:"admonition",code:"code",h2:"h2",h3:"h3",li:"li",ol:"ol",p:"p",strong:"strong",ul:"ul",...(0,t.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n.h2,{id:"overview",children:"Overview"}
1),"\n",(0,r.jsx)(n.p,{children:"This guide walks you through configuring SAML 2.0 Single Sign-On (SSO) between your Identity Provider (IdP) and Bambuser Virtual Commerce. Follow these steps to enable secure authentication for your organization."}),"\n",(0,r.jsx)(n.admonition,{title:"Alternative for Microsoft Azure Users",type:"tip",children:(0,r.jsxs)(n.p,{children:["If you're using Microsoft Azure, we recommend using our ",(0,r.jsx)(n.a,{href:"/live/microsoft-sso",children:"Microsoft Azure AD integration"})," for a more seamless experience with native OIDC support and automated user provisioning."]})}),"\n",(0,r.jsx)(n.h2,{id:"step-1-verify-prerequisites",children:"Step 1: Verify Prerequisites"}),"\n",(0,r.jsx)(n.p,{children:"Before starting, ensure you have:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Administrative access to your organization's Identity Provider (IdP)"}),"\n",(0,r.jsx)(n.li,{children:"A verified domain for user email addresses"}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"Manage Users"})," permission in Bambuser dashboard ",(0,r.jsx)("span",{class:"remark-label","data-label":"Optional"})]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-2-configure-your-identity-provider",children:"Step 2: Configure Your Identity Provider"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:[(0,r.jsx)(n.strong,{children:"Log in"})," to your IdP's administrative console"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.strong,{children:"Create a new SAML 2.0 application"})}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Application Name: ",(0,r.jsx)(n.code,{children:"Bambuser Virtual Commerce"})]}),"\n",(0,r.jsxs)(n.li,{children:["Entity ID/Issuer: ",(0,r.jsx)(n.code,{children:"bambuser_saml_service_provider"})]}),"\n",(0,r.jsxs)(n.li,{children:["Reply URL (ACS URL):","\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["US: ",(0,r.jsx)(n.code,{children:"https://svc-prod-us.liveshopping.bambuser.com/functions/auth/sso/saml/callback"})]}),"\n",(0,r.jsxs)(n.li,{children:["EU: ",(0,r.jsx)(n.code,{children:"https://svc-prod-eu.liveshopping.bambuser.com/functions/auth/sso/saml/callback"})]}),"\n"]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.strong,{children:"Configure User Attributes"})}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Map the following attributes:","\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"email"})," \u2192 ",(0,r.jsx)(n.code,{children:"user.email"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"firstName"})," \u2192 ",(0,r.jsx)(n.code,{children:"user.firstName"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"lastName"})," \u2192 ",(0,r.jsx)(n.code,{children:"user.lastName"})]}),"\n"]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:[(0,r.jsx)(n.strong,{children:"Download the IdP Metadata"})," (if available) or note down:"]}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"IdP Entity ID/Issuer URL"}),"\n",(0,r.jsx)(n.li,{children:"SSO URL (SAML Entrypoint)"}),"\n",(0,r.jsx)(n.li,{children:"X.509 Certificate (PEM format)"}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-3-share-configuration-with-bambuser",children:"Step 3: Share Configuration with Bambuser"}),"\n",(0,r.jsx)(n.p,{children:"Contact your Bambuser representative and provide the following information:"}),"\n",(0,r.jsx)(n.h3,{id:"required-information",children:"Required Information"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Domain"}),": Your organization's email domain (e.g., ",(0,r.jsx)(n.code,{children:"yourcompany.com"}),")"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"SAML Entrypoint URL"}),": Your IdP's SAML SSO URL"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"IdP Issuer"}),": Your IdP's entity ID"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"X.509 Certificate"}),": Your IdP's public certificate (PEM format)"]}),"\n"]}),"\n",(0,r.jsx)(n.h3,{id:"optional-information",children:"Optional Information"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Audience"}),": Your application ID (if required by your IdP)"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Issuer ID"}),": If different from the IdP Issuer"]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-4-configure-user-access",children:"Step 4: Configure User Acce
1ss"}),"\n",(0,r.jsx)(n.h3,{id:"option-a-manual-user-management-default",children:"Option A: Manual User Management (Default)"}),"\n",(0,r.jsx)(n.p,{children:"Manage users/roles manually in the Bambuser dashboard."}),"\n",(0,r.jsx)(n.p,{children:"For each new user:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Add them to your IdP"}),"\n",(0,r.jsx)(n.li,{children:"Manually create their account in the Bambuser dashboard"}),"\n",(0,r.jsx)(n.li,{children:"Assign appropriate roles and permissions on the Bambuser dashboard"}),"\n"]}),"\n",(0,r.jsx)(n.h3,{id:"option-b-group-based-management-recommended",children:"Option B: Group-based Management (Recommended)"}),"\n",(0,r.jsx)(n.admonition,{type:"note",children:(0,r.jsx)(n.p,{children:"Only available for Live and Video Consultation at the moment. We are working on adding support for Shoppable Video and Chat in the future."})}),"\n",(0,r.jsx)(n.p,{children:"Manage users/roles through groups in your IdP."}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["In your IdP, create groups for different permission levels (e.g., ",(0,r.jsx)(n.code,{children:"bambuser-owner"}),", ",(0,r.jsx)(n.code,{children:"bambuser-moderator"}),")"]}),"\n",(0,r.jsx)(n.li,{children:"Share the group names with your Bambuser representative"}),"\n",(0,r.jsx)(n.li,{children:"Bambuser team will map these groups to existing roles in Bambuser ecosystem"}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-5-test-and-verify-your-integration",children:"Step 5: Test and Verify Your Integration"}),"\n",(0,r.jsx)(n.p,{children:"Once the SAML configuration is completed by Bambuser on your workspace, you can test the integration by logging in to the Bambuser dashboard."}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.strong,{children:"Test authentication flow"})}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Navigate to Bambuser dashboard ",(0,r.jsx)(n.a,{href:"https://lcx.bambuser.com",children:(0,r.jsx)("span",{class:"remark-label","data-label":"Global Login"})})," ",(0,r.jsx)(n.a,{href:"https://lcx-eu.bambuser.com",children:(0,r.jsx)("span",{class:"remark-label","data-label":"EU Login"})})]}),"\n",(0,r.jsx)(n.li,{children:"Enter a test user's email"}),"\n",(0,r.jsx)(n.li,{children:"Verify redirection to your IdP"}),"\n",(0,r.jsx)(n.li,{children:"Complete authentication"}),"\n",(0,r.jsx)(n.li,{children:"Confirm successful login to Bambuser"}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.strong,{children:"Verify user attributes"})}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Check that user details (name, email) are correctly passed"}),"\n",(0,r.jsx)(n.li,{children:"Verify role assignments"}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.admonition,{title:"Test on Staging",type:"note",children:[(0,r.jsx)(n.p,{children:"If you have a separate Bambuser workspace for testing, you can ask us to setup a separate SAML integration for testing."}),(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Use a test domain (e.g., ",(0,r.jsx)(n.code,{children:"test.yourcompany.com"}),") to avoid impacting production users"]}),"\n",(0,r.jsx)(n.li,{children:"Create test users in your IdP"}),"\n"]})]}),"\n",(0,r.jsx)(n.h2,{id:"optional-automated-user-provisioning-scim",children:"Optional: Automated User Provisioning (SCIM)"}),"\n",(0,r.jsxs)(n.p,{children:["For organizations requiring automated user provisioning and deprovisioning, you can implement a custom SCIM (System for Cross-domain Identity Management) integration using our ",(0,r.jsx)(n.a,{href:"https://liveshopping-api.bambuser.com/v1/docs/api/one-to-many#section/Authentication",children:"public API"}),". This allows for:"]}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Automatic user creation when added to your IdP"}),"\n",(0,r.jsx)(n.li,{children:"Role and permission synchronization"}),"\n",(0,r.jsx)(n.li,{children:"Immediate access revocation when users are deprovisioned"}),"\n"]}),"\n",(0,r.jsx)(n.p,{children:"To implement SCIM integration:"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsx)(n.li,{children:"Review our API documentation for user management endpoints"}),"\n",(0,r.jsx)(n.li,{children:"Develop a SCIM service that interfaces with your IdP"}),"\n",(0,r.jsx)(n.li,{children:"Contact support to enable the necessary API access"}),"\n"]}),"\n",(0,r.jsx)(n.admonition,{type:"note",children:(0,r.jsx)(n.p,{children:"SCIM implementation requires development resources and is recommended for organizations with significant user management needs."})}),"\n",(0,r.jsx)(n.h2,{id:"support",children:"Support"}),"\n",(0,r.jsx)(n.p,{children:"For assistance, contact:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Your dedicated Bambuser representative"}),"\n",(0,r.jsxs)(n.li,{children:["Or our support team at ",(0,r.jsx)(n.a,{href:"mailto:[email protected]",children:"[email protected]"}),' (Subject: "Custom SAML Integration")']}),"\n"]})]})}function u(e={}){const{wrapper:n}={...(0,t.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(c,{...e})}):c(e)}},28453(e,n,i){i.d(n,{R:()=>o,x:()=>a});var s=i(96540);const r={},t=s.createContext(r);function o(e){const n=s.useContext(t);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:o(e.components),s.createElement(t.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.