# Configuring SAML with Keycloak

### Step 1: Create a new client in Keycloak

1. Log in to your Keycloak admin console.
2. Navigate to the **Clients** section and click **Create**.
3. In the **Client ID** field, enter the **Metadata URL** from the [DocuSeal SAML SSO](https://docuseal.com/settings/sso) page.
4. In the **Home URL** field, enter the **Single Sign On URL** from the [DocuSeal SAML SSO](https://docuseal.com/settings/sso) page.
5. In the **Valid Redirect URIs** field, enter your domain URL with a wildcard, such as:

```
http://your-domain/*
```

### Step 2: Configure client settings

1. In the newly created client settings, set the **Name ID Format** to **email**.
2. Disable the **Client Signature Required** option in the **Client** \> **Keys** section.

### Step 3: Retrieve SAML XML metadata

1. Go to your **Realm Settings** and open the **SAML XML Metadata**.
2. Copy the **Realm** location URL from the XML and save this URL in the DocuSeal **SSO Service URL** form field. This URL will look something like this:

```
https://your-domain-keycloak.com/realms/Realm-Name/protocol/saml
```

### Step 4: Retrieve and configure the certificate

1. Go to your **Realm** and navigate to the **Keys** section.
2. Copy the certificate and save it in the DocuSeal application SAML form.

Ensure that the email addresses of your users in DocuSeal match the assigned Keycloak user email addresses.   
 This is crucial for the SAML SSO to function correctly.