You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置IdentityServer3以传递Okta SAML令牌的所有声明至客户端?

How to Pass All SAML Claims from Okta to Clients via IdentityServer3

Absolutely! You can configure IdentityServer3 to forward all claims from your Okta SAML token to client applications—let’s break down the key steps to make this work:

1. Configure Sustainsys.Saml2 to Preserve All Claims

First, make sure your Sustainsys.Saml2 setup in IdentityServer3 isn’t filtering out claims unintentionally. The critical setting here is SaveTokens = true, which ensures the full set of claims from Okta is retained. You can also adjust the ClaimTypeMap to either keep default mappings or preserve Okta’s original claim names:

var saml2Options = new Saml2AuthenticationOptions
{
    SPOptions = new SPOptions { EntityId = new EntityId("your-identityserver-sp-entity-id") },
    IdentityProviders = new List<IdentityProvider>
    {
        new IdentityProvider(new EntityId("your-okta-idp-entity-id"), saml2Options.SPOptions)
        {
            LoadMetadata = true,
            MetadataLocation = "https://your-okta-domain.com/app/your-app-id/sso/saml/metadata",
        }
    },
    SaveTokens = true, // Critical: keeps all original claims from Okta
    ClaimTypeMap = new Dictionary<string, string>
    {
        // Keep default mappings or add custom ones (e.g., map Okta's email to standard claim type)
        {"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress", ClaimTypes.Email}
        // Leave out entries for claims you want to retain in their original Okta format
    }
};
app.UseSaml2Authentication(saml2Options);

2. Create a Custom ProfileService to Pass All Claims

IdentityServer3’s default profile service only includes a minimal set of core claims. To forward everything from the Okta SAML token, you’ll need a custom IProfileService that copies all claims from the external identity into the issued token:

public class CustomProfileService : IProfileService
{
    public Task GetProfileDataAsync(ProfileDataRequestContext context)
    {
        // Grab all claims from the user's external identity (from Okta)
        var allExternalClaims = context.Subject.Claims.ToList();
        
        // Add all of them to the claims that will be sent to the client
        context.IssuedClaims.AddRange(allExternalClaims);
        
        return Task.CompletedTask;
    }

    public Task IsActiveAsync(IsActiveContext context)
    {
        context.IsActive = true;
        return Task.CompletedTask;
    }
}

Then register this service in your IdentityServer3 setup:

var factory = new IdentityServerServiceFactory();
// Replace the default profile service with your custom one
factory.ProfileService = new Registration<IProfileService>(typeof(CustomProfileService));

3. Update Client Configuration to Allow All Claims

Make sure your client application is configured to receive all claims. In your Client definition, set AllowAccessToAllClaims = true and include any relevant scopes that align with your Okta claims:

new Client
{
    ClientId = "sample-mvc-client",
    ClientName = "Sample MVC Application",
    Flow = Flows.Hybrid,
    RedirectUris = { "https://your-mvc-app-url/signin-oidc" },
    PostLogoutRedirectUris = { "https://your-mvc-app-url/signout-callback-oidc" },
    AllowedScopes = new List<string>
    {
        IdentityServerConstants.StandardScopes.OpenId,
        IdentityServerConstants.StandardScopes.Profile,
        IdentityServerConstants.StandardScopes.Email
        // Add any custom scopes that map to your Okta-specific claims
    },
    AllowAccessToAllClaims = true // Ensures all claims are sent to the client
}

4. Double-Check Claim Transformation

If you’re still missing claims, verify that Sustainsys.Saml2 isn’t transforming or dropping them. If you want to keep Okta’s original claim names (instead of mapping to standard .NET claim types), remove those entries from the ClaimTypeMap in your Sustainsys setup.

Once you’ve applied these changes, your client application should receive all the claims that Okta sends via the SAML token, just like when you connected it directly to Okta.

内容的提问来源于stack exchange,提问作者Colin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:44:23