SAML 2.0
SP Entity ID
https://kgfbuilds.dev/sso/saml/metadata (proposed; not yet registered with any IdP)
ACS (Assertion Consumer Service) URL
https://kgfbuilds.dev/sso/saml/acs — endpoint not yet implemented
SLO (Single Logout) URL
https://kgfbuilds.dev/sso/saml/slo — endpoint not yet implemented
SP X.509 signing certificate
Generate with openssl, register fingerprint with IdP.
SP metadata XML
Generated from the above once cert is issued.
IdP metadata XML (from agency)
Provided by the IdP after onboarding approval.
Allow-listed redirect URIs registered with IdP
IdP-side configuration; depends on agency provisioning.
Attribute mapping agreement (NRIC / email / name)
Negotiated per agency; documented in the IdP's integration guideline.
Signed integration agreement / MoU with the IdP
Hard pre-requisite. No agreement = no test environment access.
