Single Sign-on authentication
- SAML SSO capabilities
- Setting up SAML SSO for your Mapbox account
- Identity providers that support SAML2.0
- Configuring your identity provider
- Configuring user roles in your identity provider
- Enabling SAML SSO for the Mapbox account
- Validating the SAML SSO integration
- Enforcing SAML SSO authentication
- Deleting SAML SSO integration
All users who log in to an account with the account's password assume Root user privileges by default, and can access and update the account's settings. But, if the account has enabled SAML Single Sign-On authentication, two user roles are available:
Root and Admin
These user roles are assigned to users in an identity provider (like Okta). For accounts with SSO enabled, only users with the Root role will be able to access and update settings as described below.
Manage your organization's access to Mapbox accounts while adding another level of security with SAML Single sign-on (SSO). SSO enables members of your organization to authenticate into a Mapbox account through any trusted, third-party identity provider that supports the SAML2.0 protocol.
SAML SSO capabilities
| Supported | Not Supported |
|---|---|
|
|
Setting up SAML SSO for your Mapbox account
SAML Single sign-on for Mapbox can be configured with any identity provider that supports the SAML 2.0 protocol. Integrate the Mapbox SAML applications offered by Okta, Azure AD, and OneLogin for a streamlined setup and IdP specific documentation, or learn more about the general steps for setting up SSO with any identity provider below.
Okta
- Okta Integration Network (OIN): Mapbox Okta verified SAML app
- Tutorial: How to configure SAML 2.0 with Mapbox
Azure Active Directory
OneLogin
- OneLogin App Store: A Mapbox SAML app is available. Log in to your OneLogin portal, navigate to the Administration panel, click "Browse app catalog", and search for "Mapbox".
Identity providers that support SAML2.0
You can create a custom SAML app for Mapbox if there is not a Mapbox SAML application available in your IdP. The setup workflow and terminology used by each identity provider can be unique, but there are general themes:
- Log in to the Mapbox account you want to set up with SSO authentication
- Navigate to the account's SSO setup page
- In your identity provider (IdP), create a new SAML application
- Copy and paste the required details in the Configure your identity provider section of the Mapbox SSO setup page into your IdP’s configuration workflow
- Create a custom attribute within your app that will pass the required user roles from your IdP to Mapbox in the SAML assertion.
- Copy and paste the required details from your SAML app within your IdP into the Setup SAML single sign-on for Mapbox section of the SSO setup page
- Click Enable single sign-on to save the integration
- Validate the integration is working as expected by assigning yourself one of the required user roles for the Mapbox SAML app. If required, assign yourself the application within your IdP.
- Assign users to the Mapbox application in your IdP, and assign a required Mapbox user role to each user (or user group)
- Follow the recommendations for enforcing SAML authentication, then flip the Activate Mapbox SSO toggle from
OfftoOnto immediately terminate all sessions.
Configuring your identity provider
Log into your identity provider with the required administrative privileges, then create a custom SAML2.0 application for Mapbox. See the following external links for IdP specific instructions:
In this new application, enter the following values from the Mapbox SSO setup page:
Single sign-on URL, also could be referred to as theSSO URL,Assertion Consumer Service (ACS) URL,Application ACS URL,Reply URL,Callback URL, orPost-back URLin your IdP.Audience Restriction, also could be referred to asAudience URI,SP Entity ID,Identifier, orApplication SAML Audiencein your IdP.
Configuration notes
- The application username must be in email format
- The SHA256 encryption algorithm is required
- One of the supported user roles must be present in the SAML assertion for a successful SAML login.
Configuring user roles in your identity provider
Through SAML SSO you can assign users roles that provide certain permissions in the Mapbox Account and Studio apps that are also enforced by all Mapbox APIs. User roles are assigned in the identity provider and transferred to Mapbox in the SAML assertion. The available user roles are:
| Role | Permissions | Typical users |
|---|---|---|
Root | Users with the Root role can access invoices, read and write to account settings, and read and write to all resources and APIs. | IT Admins, Product Owners, CTOs |
Admin | Users with the Admin role can read and write to all resources and APIs. They cannot access invoices, nor can they read or write to account settings. | Developers, Designers, Project contributors |
Many identity providers use custom attributes and attribute statements for roles. The attribute key name and role values are case-insensitive. Typically, roles can be assigned to individuals or groups. Consult the documentation for your specific IdP, such as the Okta documentation for Mapbox SAML apps for details.
Enabling SAML SSO for the Mapbox account
To complete the initial connection between your identity provider and mapbox.com, enter the required information in the Mapbox account's SSO setup page:
Identity Provider sign-on URL, also could be referred to asSSO URL,SAML endpoint, orSSO sign-in URLin your IdPIssuer ID, also could be referred to asEntity ID,Issuer, orIssuer URLin your IdPX.509 Certificate, pasted as text into the field.
Be sure to include — BEGIN CERTIFICATE — and — END CERTIFICATE — when pasting your X.509 certificate into the Mapbox form. You may need to open the X.509 certificate in a text editor to accurately copy the full body.
Click Enable single sign-on to submit the form. You will be prompted to re-authenticate.
Validating the SAML SSO integration
Once you have saved the integration, return to your identity provider to assign the application to yourself and/or another member of the organization for testing. When assigned, try clicking the tile, "chiclet", or link for your Mapbox app to log in from your identity provider's portal. If you receive an error when attempting to log in with SAML, you can adjust the settings by clicking edit single sign on.
Enforcing SAML SSO authentication
Enabling SSO for an account does not invalidate password authentication. The account's password is still a valid authentication method to make sure your organization's transition period to SAML authentication is seamless, and that direct password access to the account is available in case your identity provider has a service outage. Note that any users logging in with the account's password (and optional 2FA) will assume the Root user role.
To encourage your users to transition from password-based authentication to SAML login through your IdP, we recommend the following once the integration has been tested successfully:
- Assign yourself the
Rootuser role in your IdP so you will have access to settings - Assign most other users the
Adminuser role so they will not have access to settings - Change the email for the account to an email address that the
Rootuser(s) can access - Save the new password in a safe location with least-privilege access (identity provider, shared password manager, IT vault)
- If 2FA is enabled for the account, either turn it off or save the recovery codes with the new password
- Announce to your organization that SAML SSO will be the primary mechanism for Mapbox access as of a future date. Encourage all users to test that they can access Mapbox with SAML before that date.
- On the date of enforcement, toggle the
Activate single sign onbutton on the account's Security Settings page to immediately terminate all the account's active sessions. - Change the password for the account, making the previous password invalid. As with activating Mapbox SSO, when the account's password is changed, all active sessions will be terminated. We recommend taking these two steps at the same time to prevent confusion for your users.
Once SSO is activated and the password has been changed, these updates should effectively push all application users to authenticate with Single Sign-On, as they'll no longer have the password.
Questions about setting up SAML SSO? Visit the troubleshooting section for recommendations and next steps to contact support.
Deleting SAML SSO integration
You have the option to delete your SAML SSO integration. This is something you would need to do only in a rare situation -- generally, only if your organization has set up single sign-on with a test account. Some identity providers can only be associated with a single Mapbox account. If you or your IT team has associated an IdP with a test account, we recommend deleting that integration before beginning setup for the organization's main account.