AWS console SSO with SAML
AWS console federation is not a complete supported flow in the released Caddy Security v1.3.0 / go-authcrunch v1.3.8 runtime. The sso provider configuration, metadata generation and role menu exist, but the assume-role handler returns the literal body ASSUME ROLE. It does not create, sign or submit the SAML assertion required by AWS. The same handler remains incomplete in standalone go-authcrunch v1.3.11.
For a working application integration, use portal JWT authorization, direct OAuth policies or the released OIDC provider. For users signing into AuthCrunch through Entra/JumpCloud, use upstream SAML identity providers; that is a separate, implemented flow.
AWS menu and metadata stop before a completed assertion flow. The released SSO app parses configured provider/key material, serves metadata to an authenticated portal session, and displays AWS role choices. Its assume-role handler returns a placeholder rather than a signed SAML assertion. The dashed boundary below identifies missing behavior, not a configuration step that completes federation.
AWS SSO
AWS accepts SAML assertions from a configured identity provider, including permitted IAM role/provider ARN pairs. Its console federation procedure describes that AWS-side protocol. Configuring an AuthCrunch metadata document does not implement the missing assertion issuance or grant an AWS console session.
The released AuthCrunch routes under a portal mounted at /auth/ are:
| Route | Implemented behavior |
|---|---|
/auth/apps/sso/aws | Role-selection menu for an authenticated, cached portal session |
/auth/apps/sso/aws/metadata.xml | XML metadata with the configured entity ID, signing certificate and locations |
/auth/apps/sso/aws/assume/<account>/<role> | Placeholder response; no AWS SAML assertion |
The menu recognizes roles shaped as aws/<account>/<role>. It does not turn these values into AWS permissions. The metadata route also requires a live portal session. Despite a source comment calling it admin-only, the handler does not add an admin-role check; do not treat that comment as an access-control guarantee.
Configuration
For inspecting the implemented metadata/menu only, define and enable a provider:
sso provider aws {
entity_id urn:authcrunch:aws
driver aws
private key /etc/authcrunch/sso/signing-key.pem
cert /etc/authcrunch/sso/signing-cert.pem
location https://auth.example.com/auth/apps/sso/aws
}
Add enable sso provider aws inside the portal. The only released driver is aws. The private key must use a PKCS#8 PEM PRIVATE KEY block; the certificate uses a PEM CERTIFICATE block. A generated key or downloadable XML does not make the assume-role endpoint functional.
Keep private key material outside published assets and restrict access to the service account. Do not deploy this partial flow as your AWS login solution or promise session-duration/session-tag controls that the handler does not issue.
The implementation boundary is visible in the released handler and metadata implementation. Track implementation and a tested signed-assertion flow before revising the support claim.
Agentic Prompts
Copy a prompt into your LLM to explore this topic. Each prompt prioritizes upstream repository guidance and code over this page, and asks for version-aware reasoning.
Locate the implementation boundary
Help me understand SAML application SSO: released status.
Primary authorities (take precedence over website documentation):
https://github.com/greenpau/caddy-security/blob/main/AGENTS.md
https://github.com/greenpau/caddy-security/tree/main/.codex/skills
https://github.com/greenpau/go-authcrunch/blob/main/AGENTS.md
https://github.com/greenpau/go-authcrunch/tree/main/.codex/skills
Read each repository's root AGENTS.md first, then any scoped AGENTS.md that
applies to inspected paths. Read the relevant SKILL.md files and follow their
implementation and test references.
Relevant skills to locate: configuration-sso-app, saml-identity-provider.
Secondary reference:
https://docs.authcrunch.com/docs/apps/sso_saml
If a source is inaccessible, ask me to paste its relevant text. Identify the
versions your answer applies to; main may be newer than my release. Resolve
disagreements using code and tests, and flag unverified claims. Use synthetic
credentials and redacted examples; explain proposed checks before any changes.
Compare external SAML login with the portal’s AWS SAML SSO app feature. Trace
the assume-role handler in my installed release and current main. Identify
whether it issues a signed assertion or a placeholder response; do not treat
valid metadata or a visible role menu as working AWS federation.
Read an SSO declaration
Help me understand SAML application SSO: released status.
Primary authorities (take precedence over website documentation):
https://github.com/greenpau/caddy-security/blob/main/AGENTS.md
https://github.com/greenpau/caddy-security/tree/main/.codex/skills
https://github.com/greenpau/go-authcrunch/blob/main/AGENTS.md
https://github.com/greenpau/go-authcrunch/tree/main/.codex/skills
Read each repository's root AGENTS.md first, then any scoped AGENTS.md that
applies to inspected paths. Read the relevant SKILL.md files and follow their
implementation and test references.
Relevant skills to locate: configuration-sso-app, saml-identity-provider.
Secondary reference:
https://docs.authcrunch.com/docs/apps/sso_saml
If a source is inaccessible, ask me to paste its relevant text. Identify the
versions your answer applies to; main may be newer than my release. Resolve
disagreements using code and tests, and flag unverified claims. Use synthetic
credentials and redacted examples; explain proposed checks before any changes.
Annotate a synthetic AWS provider declaration: name, entity_id, driver, PEM
certificate, PKCS8 private key, and externally reachable location. Follow the
portal enablement and mount prefix. Explain parser acceptance, key loading,
metadata generation, and assertion issuance as separate checks.
Distinguish menu roles from cloud authorization
Help me understand SAML application SSO: released status.
Primary authorities (take precedence over website documentation):
https://github.com/greenpau/caddy-security/blob/main/AGENTS.md
https://github.com/greenpau/caddy-security/tree/main/.codex/skills
https://github.com/greenpau/go-authcrunch/blob/main/AGENTS.md
https://github.com/greenpau/go-authcrunch/tree/main/.codex/skills
Read each repository's root AGENTS.md first, then any scoped AGENTS.md that
applies to inspected paths. Read the relevant SKILL.md files and follow their
implementation and test references.
Relevant skills to locate: configuration-sso-app, saml-identity-provider.
Secondary reference:
https://docs.authcrunch.com/docs/apps/sso_saml
If a source is inaccessible, ask me to paste its relevant text. Identify the
versions your answer applies to; main may be newer than my release. Resolve
disagreements using code and tests, and flag unverified claims. Use synthetic
credentials and redacted examples; explain proposed checks before any changes.
Explain how aws/account_id/role_name values build menu choices. Compare portal
authentication, metadata access, role display, a signed SAML assertion, and
AWS trust policy evaluation. Inspect actual role checks rather than trusting
an admin-only comment. State which steps remain unimplemented in my version.
Inspect metadata without exposing keys
Help me understand SAML application SSO: released status.
Primary authorities (take precedence over website documentation):
https://github.com/greenpau/caddy-security/blob/main/AGENTS.md
https://github.com/greenpau/caddy-security/tree/main/.codex/skills
https://github.com/greenpau/go-authcrunch/blob/main/AGENTS.md
https://github.com/greenpau/go-authcrunch/tree/main/.codex/skills
Read each repository's root AGENTS.md first, then any scoped AGENTS.md that
applies to inspected paths. Read the relevant SKILL.md files and follow their
implementation and test references.
Relevant skills to locate: configuration-sso-app, saml-identity-provider.
Secondary reference:
https://docs.authcrunch.com/docs/apps/sso_saml
If a source is inaccessible, ask me to paste its relevant text. Identify the
versions your answer applies to; main may be newer than my release. Resolve
disagreements using code and tests, and flag unverified claims. Use synthetic
credentials and redacted examples; explain proposed checks before any changes.
Help me inspect public entity IDs, SSO locations, signing certificates, and
browser binding in generated metadata. Explain certificate versus private-key
handling and how a different portal prefix affects URLs. Keep test material
synthetic and distinguish a reachable authenticated metadata route from a
public metadata endpoint.
Choose an integration with evidence
Help me understand SAML application SSO: released status.
Primary authorities (take precedence over website documentation):
https://github.com/greenpau/caddy-security/blob/main/AGENTS.md
https://github.com/greenpau/caddy-security/tree/main/.codex/skills
https://github.com/greenpau/go-authcrunch/blob/main/AGENTS.md
https://github.com/greenpau/go-authcrunch/tree/main/.codex/skills
Read each repository's root AGENTS.md first, then any scoped AGENTS.md that
applies to inspected paths. Read the relevant SKILL.md files and follow their
implementation and test references.
Relevant skills to locate: configuration-sso-app, saml-identity-provider.
Secondary reference:
https://docs.authcrunch.com/docs/apps/sso_saml
If a source is inaccessible, ask me to paste its relevant text. Identify the
versions your answer applies to; main may be newer than my release. Resolve
disagreements using code and tests, and flag unverified claims. Use synthetic
credentials and redacted examples; explain proposed checks before any changes.
Given an application that needs real single sign-on, ask about its supported
protocols, account source, and deployed versions. Compare upstream SAML login,
supported downstream OIDC, and the partial AWS SAML app route. Identify the
evidence required before selecting an approach and avoid inventing assertion
or session-tag capabilities.
Source Code References
Start with the code search, then follow the parser, runtime, and tests relevant
to this topic. These links target main; use GitHub's branch/tag selector to
compare them with your installed release.
- Search this topic in both repositories — searches topic-specific symbols and paths across both codebases.
- caddy-security: caddyfile_sso_provider.go — adapts SSO app names, AWS driver, locations, and key/certificate paths.
- caddy-security: caddyfile_sso_provider_test.go — tests SSO app configuration adaptation.
- go-authcrunch: pkg/authn/handle_http_apps_sso.go — handles the authenticated SSO menu, metadata, and assume-role placeholder.
- go-authcrunch: pkg/sso/provider.go — loads SSO certificate and private-key material and constructs metadata.
- go-authcrunch: pkg/sso/metadata.go — defines the generated SAML IdP metadata structure.
- go-authcrunch: pkg/sso/request.go — parses provider and assume-role targets from portal URLs.