Skip to main content
Odoo Community Association

SAML2 Authentication

Beta License: AGPL-3 OCA/server-auth Translate me on Weblate Try me on Runboat

Let users log into Odoo via an SAML2 identity provider.

This module allows to deport the management of users and passwords in an external authentication system to provide SSO functionality (Single Sign On) between Odoo and other applications of your ecosystem.

Benefits:

  • Reducing the time spent typing different passwords for different accounts.

  • Reducing the time spent in IT support for password oversights.

  • Centralizing authentication systems.

  • Securing all input levels / exit / access to multiple systems without prompting users.

  • The centralization of access control information for compliance testing to different standards.

Table of contents

Installation

This addon requires the python module pysaml2.

pysaml2 requires the binary xmlsec1 (on Debian or Ubuntu you can install it with apt-get install xmlsec1)

Configuration

To use this module, you need an IDP server, properly set up.

  1. Configure the module according to your IdP’s instructions (Settings > Users & Companies > SAML Providers).

  2. Pre-create your users and set the SAML information against the user.

By default, the module let users have both a password and SAML ids. To increase security, disable passwords by using the option in Settings. Note that the admin account can still have a password, even if the option is activated. Setting the option immediately remove all password from users with a configured SAML ids.

If all the users have a SAML id in a single provider, you can set automatic redirection in the provider settings. The autoredirection will only be done on the active provider with the highest priority. It is still possible to access the login without redirection by using the query parameter disable_autoredirect, as in https://example.com/web/login?disable_autoredirect= The login is also displayed if there is an error with SAML login, in order to display any error message.

If you are using Office365 as identity provider, set up the federation metadata document rather than the document itself. This will allow the module to refresh the document when needed.

Usage

Users can login with the configured SAML IdP with buttons added in the login screen.

Known issues / Roadmap

  • clean up auth_saml.request

Changelog

18.0.1.1.3 (2026-06-18)

Bugfixes

  • Fix sending a mail when configuring SAML for a user.

18.0.1.0.3 (2025-09-11)

Features

  • When using attribute mapping, only write value that changes. Not writing the value systematically avoids getting security mail on login/email when there is no real change.

18.0.1.0.2 (2025-05-13)

Bugfixes

  • Avoid redirecting when there is a SAML error.

18.0.1.0.0

Initial migration for 18.0.

Bug Tracker

Bugs are tracked on GitHub Issues. In case of trouble, please check there if your issue has already been reported. If you spotted it first, help us to smash it by providing a detailed and welcomed feedback.

Do not contact contributors directly about support or help with technical issues.

Credits

Authors

  • XCG Consulting

Contributors

Maintainers

This module is maintained by the OCA.

Odoo Community Association

OCA, or the Odoo Community Association, is a nonprofit organization whose mission is to support the collaborative development of Odoo features and promote its widespread use.

Current maintainer:

vincent-hatakeyama

This module is part of the OCA/server-auth project on GitHub.

You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute.

Release files for odoo-addon-auth-saml 18.0.1.1.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for odoo-addon-auth-saml 18.0.1.1.3.1
File Interpreter ABI Platform
odoo_addon_auth_saml-18.0.1.1.3.1-py3-none-any.whl Python 3 none any Details

Release files / odoo_addon_auth_saml-18.0.1.1.3.1-py3-none-any.whl

Download URL odoo_addon_auth_saml-18.0.1.1.3.1-py3-none-any.whl
Size 78.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
009c7ed3289b6e9d6ea2acf1de11495a93e39c8ebe6ec799a28520db6b333cc3
BLAKE2b-256 checksum
How to use checksums
1a4e46a1291f4382d3c2dc9ae112c74cb30c5f2f7df43308376b7b760a96af26
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.4

Release history Release notifications | RSS feed

This release

18.0.1.1.3.1 This release

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page