[Yandex Cloud documentation](../../../../index.md) > [Yandex Identity Hub](../../../index.md) > [Tutorials](../../index.md) > [Setting up single sign-on (SSO) for apps](../index.md) > LibreChat > SAML

# Creating a SAML app in Yandex Identity Hub for integration with LibreChat

[LibreChat](https://www.librechat.ai/) is a free open-source platform that provides an easy way to work with large language models, AI agents, and MCP servers and can be deployed in your own infrastructure. LibreChat supports the [SAML](https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language) standard to provide secure SSO for your organization's users.

For the users of your [organization](../../../concepts/organization.md) to be able to authenticate to LibreChat via [SAML](https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language) SSO, create a [SAML app](../../../concepts/applications/saml.md) in Yandex Identity Hub and configure it both in Yandex Identity Hub and LibreChat.

SAML apps can be managed by users with the `organization-manager.samlApplications.admin` [role](../../../security/index.md#organization-manager-samlApplications-admin) or higher.

{% note info %}

For successful SAML integration, configure access to your LibreChat instance over `https` using a valid TLS certificate.

{% endnote %}

To provide your organization's users with access to LibreChat:

1. [Create an app in Yandex Identity Hub](#create-app).
1. [Set up the integration](#setup-integration).
1. [Make sure the application works correctly](#validate).

## Create an app in Yandex Identity Hub {#create-app}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

  1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
  1. In the left-hand panel, select ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps**.
  1. In the top-right corner, click ![Circles3Plus](../../../../_assets/console-icons/circles-3-plus.svg) **Create application** and in the window that opens:

      1. Select the **SAML (Security Assertion Markup Language)** single sign-on method.
      1. In the **Name** field, specify a name for your new app: `librechat-saml-app`.
      1. Optionally, enter the app description and add [labels](../../../../resource-manager/concepts/labels.md).
      1. Click **Create application**.
  1. On the new app page that opens:
  
      1. Under **Identity provider (IdP) configuration**, copy and save the **Login URL** field value for later to configure the integration in LibreChat.
      1. Under **Application certificate**, click **Download certificate** to get your SAML app certificate.

          Copy the certificate file you got to the server where you deployed your LibreChat instance.

{% endlist %}

## Set up the integration {#setup-integration}

To configure LibreChat integration with the SAML app you created, complete the configuration both on the Yandex Identity Hub side and in LibreChat.

### Set up the SAML application in Yandex Identity Hub {#setup-idp}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

  1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
  1. In the left-hand panel, select ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and then, the SAML app.
  1. Set up service provider endpoints. To do this, at the top right, click ![pencil](../../../../_assets/console-icons/pencil.svg) **Edit** and in the window that opens:

      1. In the **SP EntityID ** field, specify any value, e.g., your LibreChat instance address: `https://librechat.example.com`.
      1. In the **ACS URL** field, enter this address: `https://<LibreChat_instance_address>/oauth/saml/callback`.
      1. Click **Save**.
  1. Configure mapping for the `username` attribute which will be used as the username when authenticating to LibreChat. Follow these steps:

      1. Navigate to the **Attributes** tab.
      1. In the top-right corner, click ![plus](../../../../_assets/console-icons/plus.svg) **Add attribute** and in the window that opens:

          1. In the **Attribute name** field, enter `username`.
          1. In the **Value** field, select `SubjectClaims.preferred_username`.
          1. Click **Add**.

      For more information about configuring attributes, see [Configure user and group attributes](../../../operations/applications/saml-create.md#setup-attributes).

{% endlist %}

### Set up authentication in LibreChat {#setup-sp}

On the host running your LibreChat instance, set the following environment variables in the instance runtime environment to configure the LibreChat integration with the SAML application:

Variable name | Value
--- | ---
`SAML_ENTRY_POINT` | `Login URL` value you [saved previously](#create-app).
`SAML_ISSUER` | `SP EntityID ` value you [set previously](#setup-idp) on the Yandex Identity Hub side.</br></br>Here is an example: `https://librechat.example.com`.
`SAML_CERT` | Local path to the SAML app certificate file in the runtime of your LibreChat instance, which [you saved earlier](#create-app).</br></br>Here is an example: `"/app/saml-certs/librechat-saml-app.cer"`.
`SAML_CALLBACK_URL` | `"https://<LibreChat_instance_address>/oauth/saml/callback"`
`SAML_SESSION_SECRET` | Additional secret for session security.</br></br>Generate a strong secret of at least 32 characters.
`SAML_EMAIL_CLAIM` | `"emailaddress"`
`SAML_USERNAME_CLAIM` | `"username"`
`SAML_GIVEN_NAME_CLAIM` | `"givenname"`
`SAML_FAMILY_NAME_CLAIM` | `"surname"`
`SAML_NAME_CLAIM` | `"fullname"`
`SAML_BUTTON_LABEL` | `"Login with Yandex Identity Hub"`

### Add a user {#add-user}

For your organization's users to be able to authenticate to LibreChat with Yandex Identity Hub SAML app, explicitly add these users and/or [user groups](../../../concepts/groups.md) to the SAML application:

{% note info %}

Users and groups added to a SAML application can be managed by a user with the `organization-manager.samlApplications.userAdmin` [role](../../../security/index.md#organization-manager-samlApplications-userAdmin) or higher.

{% endnote %}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

  1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
  1. In the left-hand panel, select ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select the required app.
  1. Navigate to the **Users and groups** tab.
  1. Click ![person-plus](../../../../_assets/console-icons/person-plus.svg) **Add users**.
  1. In the window that opens, select the required user or user group.
  1. Click **Add**.

{% endlist %}

{% note tip %}

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use [authentication policies](*authentication_policies).

{% endnote %}

[*authentication_policies]: Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see [Authentication policies in Yandex Identity Hub](../../../concepts/authentication-policy.md).

## Make sure your application works correctly {#validate}

To make sure both your SAML app and LibreChat integration work correctly, authenticate to LibreChat as one of the users you added to the app. Follow these steps:

1. In your browser, open the LibreChat instance login page.
1. Select login via Yandex Identity Hub.
1. Authenticate in Yandex Cloud as your organization’s user you added to the SAML app.
1. Make sure you have successfully authenticated to LibreChat.