Keyway SSO
Craft ships no built-in SAML or OpenID Connect sign-in for the control panel. This adds it.
Core SSO support exists from Craft 5.3 for Enterprise only, and it is scaffolding: no SAML provider, no generic OpenID Connect provider, and marked internal.
Keyway SSO signs people into the Craft control panel with your own identity provider over SAML 2.0 or OpenID Connect, maps the attributes and groups it receives onto Craft users and user groups, and records every attempt on a diagnostics screen inside the control panel.
It is built for the agency or IT department that has been told single sign-on is a condition of the deployment — the kind of requirement that arrives with a security policy or an audit attached.
What it does
- SAML 2.0, HTTP-POST binding for the assertion: signed assertions are required and that check cannot be switched off; encrypted assertions are implemented but unverified (no automated test, not run against a live provider); the service-provider metadata document is served from your own site.
- OpenID Connect — run end to end with Keycloak only (see "Verified against live systems"
below): Authorization Code with PKCE (
S256, always), discovery,RS256andES256id-token signatures (ES256is covered by automated tests only).httpsis required for both the issuer and the redirect URI. - Attribute and group mapping: provider attributes onto
email,username,firstName,lastName,fullNameor any custom field; provider groups onto Craft group handles by exact, prefix or suffix match. Assigning Craft user groups needs Craft Pro, because Craft itself only has user groups from Pro upwards; on Team the plugin leaves group membership untouched and says so. Everything else works on Team. - Just-in-time accounts: create on first login, update on every login, or match an account that already exists — each one its own switch. Matching an existing account also asks you to name the e-mail domains it may match, and linking to an administrator account is a second, separate opt-in: that boundary is where an account takeover would happen.
- A password fallback with an anti-lockout guard that reads your settings every time they are loaded. A combination that would leave nobody able to sign in if the provider broke has admin password login switched back on, with a warning saying so. The guard reads settings, not accounts: an emergency account that does not exist, or that has no local Craft password — as none of the accounts this plugin creates do — is not a way back in, and the guard cannot tell.
- A diagnostics screen recording every sign-in attempt that reaches a connection, with the
stage it got to, the outcome, a machine reason code (
domain_not_allowed,state_rejected, …), the attributes that arrived and the decision that was made. Provider values are masked when written, history is pruned to 30 days or 2000 rows. - Single Logout (SAML only, one direction, opt-in: it needs your provider's logout URL and an
SP private key before it does anything): when your identity provider sends a signed SAML
LogoutRequest, the plugin ends the matching Craft session. Signing out of Craft does not end the session at your identity provider, and Okta will not send such a request after an ordinary Okta sign-out — so with Okta as your only provider, plan on single sign-on, not single logout. Verified end to end against Keycloak 26.0; OpenID Connect has no logout support. - Step-by-step guides for Keycloak and Okta, written against the field names you actually see in each console. The Microsoft Entra ID guide is written from Microsoft's published documentation and is marked, in the guide itself, as not yet verified against a live tenant.
What it deliberately does not do
Stated here rather than discovered after purchase:
- Logins are started from the Craft site (SP-initiated). Provider-initiated tiles and bookmarks that jump straight into the provider do not work.
- SAML authentication requests are sent unsigned. A provider configured to require signed requests will refuse every login.
- One connection at a time — the protocol dropdown selects a single provider; there is no multi-provider mode.
- A
transientNameID format cannot be used. Accounts are recognised on later logins by their subject, and a transient NameID is a new value every time, so the second login of every user is refused. ConfigurepersistentoremailAddressat the provider. - No SCIM, no LDAP, no identity-provider role.
- Just-in-time accounts stop at five on Craft Team. That ceiling is Craft's own licence limit for the Team edition, not a limit of this plugin; a site that expects to provision more users needs Craft Pro.
- The plugin has no field for an SP certificate, so a site using encrypted assertions has to hand that certificate to its provider out of band.
- Clock-skew tolerance tops out at 120 seconds and the time checks themselves cannot be switched off.
Verified against live systems
- SAML with Keycloak 26.0 — verified end to end on 17 September 2026 against a live realm and a live Craft install: sign-in, attribute and group mapping, and account creation.
- SAML with Okta (Integrator Free Plan) — verified end to end on 17 September 2026 against a live tenant and a fresh Craft 5.11 install on default settings: the first sign-in created the account just in time with the mapped group, the second updated it and reached the control panel.
- OpenID Connect with Keycloak 26.0 — verified end to end on 30 September 2026 against a live
Craft 5.11 install on PHP 8.2, over HTTPS with certificate verification: Authorization Code
with PKCE (
S256), a confidential and a public client,RS256id tokens, first and repeat sign-in, and refusals (wrong client secret, domain not allowed, no matching group). Not covered:ES256id tokens, key rotation, and any OpenID Connect provider other than Keycloak. - Microsoft Entra ID — the guide is written and not yet verified against a live tenant; the guide itself says so.
Documentation, including the full list of limits: https://keyway.aphexcoding.tech/
Craft CMS is a trademark of Pixel & Tonic; Okta, Microsoft Entra ID and Keycloak are trademarks of their respective owners. Keyway SSO is not affiliated with or endorsed by any of them.
Standard
Plus $39/year after one year.
To install this plugin, copy the command above to your terminal.
This plugin doesn't have any reviews.



