For customers whose self-hosted deployments include a full API server and frontend deployment via helm,
this page covers only part of the SAML setup. After completing this guide, refer to
the Cloud Auth documentation to complete setup.
If your Chalk web dashboard is not https://chalk.ai, check your team’s dashboard for the correct values.
These can be found under Single Sign-On in the team settings:
Single Sign-On URL: This should start with your custom URL and not chalk.ai, but retain the same URL path.
Audience URI: This should start with your custom URL and not chalk.ai.
Chalk’s SAML Certificate is regenerated for each custom web dashboard. If your team did not generate this themselves, contact Chalk for support.
Reply URL (Assertion Consumer Service URL): https://chalk.ai/api/auth/login/saml
Sign-On Url: https://chalk.ai/login
Relay State: Leave blank
Logout URL: https://chalk.ai/api/auth/signout
Set Up SAML (Attributes & Claims): This section will depend on your own Entra ID setup and what attributes are in use. However, Chalk requires the following to be set:
givenname
surname
Unique User Identifier: This should match your user’s primary email address attribute
Set Up Application: No inputs are necessary in this section. Download the Federation Metadata XML, which you need in the next section.
Test single sign-on: You cannot do this until you connect Chalk to your application in the next section.
You can connect your Entra ID application with Chalk from Single Sign-On in the team settings. In the
SAML Configurations section, select Add configuration. To integrate your SAML application with Chalk,
select Or upload metadata XML and upload the Federation Metadata XML from the previous section. The form fills in: