One login. The right permissions. Always current.
AuthSaml connects Matomo to your identity provider: SAML 2.0 single sign-on, SCIM 2.0 on-/offboarding and site permissions driven by your IdP groups — for Okta, Microsoft Entra ID, Keycloak and any SAML provider.
Latest v2.1.0 · Matomo ≥ 5.0.0
One login for everything
Your users sign in with their company account — SP- or IdP-initiated, optionally with single logout and forced SSO. Accounts are created automatically on first login.
Permissions from IdP groups
Group → sites → role: the mapping in the admin area turns your IdP into your access management. Synchronized on every login and every SCIM change — manually assigned permissions stay untouched if you want.
Real-time offboarding
SCIM 2.0 deactivates departed employees instantly: sessions are terminated, permissions revoked — no login involved, no manual cleanup.
No lockout risk
Strict mode, signed assertions and replay protection are the defaults — yet superusers always keep a break-glass login. An IdP outage never takes down your Matomo access.
Diagnostics instead of support tickets
The admin page shows recent SSO errors including the groups and attributes actually received. You see within seconds why a login fails — and what to fix in the IdP.
Click to enlarge
Any SAML 2.0 compliant IdP. Tested with Okta, Microsoft Entra ID and Keycloak; compatible with ADFS, Google Workspace, OneLogin and others. GitHub does not offer SAML as an IdP — use a federating broker such as Keycloak there.
No. Account creation and permission sync work entirely through the SAML login (just-in-time). SCIM is worth it when offboarding must take effect immediately instead of at the next login — on Microsoft Entra ID, automatic provisioning requires a P1 license.
Yes. In the default "managed" mode, AuthSaml only revokes permissions it granted itself — everything assigned manually stays untouched. If you want the IdP as the single source of truth, choose the authoritative mode.
Nobody gets locked out: superusers always keep a break-glass password login, the password login policy is configurable, and the license check never blocks sign-in.
Typically under 15 minutes: register the SP metadata URL in your IdP, paste the IdP metadata URL into the plugin (auto-import with daily refresh), create your group mappings. Step-by-step guides for Okta, Entra ID and Keycloak are included.
Only if you explicitly enable it and define a dedicated IdP group. A safeguard option prevents demoting existing superusers — the last superuser is never removed.
They are adopted, not duplicated: on the first SSO login, AuthSaml matches the account by login or email address and links it to the IdP permanently. The password is kept, and manually assigned site permissions stay untouched in the default mode — the plugin only ever revokes what it granted itself. Existing superusers are never demoted. SCIM provisioning adopts existing accounts the same way, so you can introduce SSO on a running Matomo installation without recreating users or losing permissions.
Because it covers more: beyond SAML sign-in, AuthSaml includes permission management through IdP groups and a full SCIM 2.0 server for automatic on- and offboarding — capabilities that plain SSO plugins lack or that require extra tooling. One license replaces manual user administration across the entire lifecycle.
-
01
Download the Feinwerk connector and unzip it into your Matomo's
plugins/directory, then activate it. - 02 Open its settings and set the marketplace URL and your instance token.
- 03 Open the Feinwerk Plugins screen, find AuthSaml, and click Install.
AuthSaml
AuthSaml turns your identity provider into the single source of truth for Matomo: sign-in via SAML 2.0 single sign-on, user lifecycle via SCIM 2.0, and site permissions driven by your IdP groups. Works with Okta, Microsoft Entra ID, Keycloak, ADFS, Google Workspace and any other SAML 2.0 provider.
Sign-in and permissions from one source
On the first SSO login, AuthSaml creates the Matomo account automatically (just-in-time provisioning). On every following login it synchronizes site permissions from the group claims: in the admin area you map IdP groups to Matomo sites and roles (view, write, admin) — from then on, access is managed in your IdP alone. Alternatively or additionally, AuthSaml reads permissions from a direct attribute (e.g. matomo_access = "view:1,4;write:2").
Three sync modes control how strictly the IdP leads: additive (only grants, never revokes), managed (revokes only what the plugin granted itself — manually assigned permissions stay untouched) or authoritative (the IdP fully defines permissions).
Offboarding that takes effect immediately
With SCIM 2.0 enabled, your IdP actively pushes users and groups to Matomo: new team members exist before their first sign-in. Departed employees are deactivated instantly — running sessions are terminated and granted permissions revoked, with no one having to remember anything. Group changes in the IdP affect site permissions immediately, without any login involved.
Secure by default — with no lockout risk
Signed assertions, RSA-SHA256, strict mode and replay protection are the defaults. At the same time, AuthSaml is built so an IdP outage never locks you out: superusers always keep a guaranteed break-glass password login, and login restrictions only apply once SAML is actually configured.
Set up in minutes
Copy the SP metadata URL into your IdP, paste the IdP metadata URL into the plugin — import and daily auto-refresh included, certificate rollover (e.g. Entra ID) is handled automatically. Create your group mappings, done. The diagnostics page shows the most recent SSO errors together with the groups and attributes actually received — no more guessing why a login fails. Console commands for automation and step-by-step guides for Okta, Entra ID and Keycloak are included.
One license, the full lifecycle
AuthSaml is deliberately positioned as a complete solution: where classic SSO plugins stop at the login, one license covers the entire user lifecycle — SAML sign-in, permission management through IdP groups, and SCIM provisioning with real-time offboarding. It replaces manual user administration and separate provisioning tools, and pays for itself quickly in teams with turnover.
-
v2.1.0 Oct 1, 2026
-
v2.0.1 Sep 30, 2026
-
v2.0.0 Sep 30, 2026