HomeGuidesAPI ReferenceChangelogDiscussions
GuidesAPI ReferenceDiscussions


## Identity Provider Configuration

## Issuer Entity ID

URL that uniquely identifies your SAML identity provider. Please provide this value to your Blend project contact. SAML assertions sent to Blend must match this value in the `<saml:Issuer>` attribute of SAML assertions.

`<saml:Issuer>{issuer}</saml:Issuer>`

## Required User Settings

AttributeData TypeDescription
`NameID`stringA unique, pseudo-random identifier for the user that will not change over time — like a user ID number.
`email`stringA verified email of the user signing in.

### Example SAML Assertions




## Optional User Attributes

AttributeData TypeDescription
`referrerID`stringEnsures the information included in a [Blend Referral](🔗) Link is effectively passed through the SAML authentication.
`originationType`enum: `MORTGAGE` `HELOC` `HELOAN`Sets the appropriate application template for the user.
`firstName`stringThe SSO user's first name.
`lastName`stringThe SSO user's last name.
`primaryPhone`noneThe SSO user's primary phone number. Blend collects a single contact number.
physicalAddressStreet`stringThe SSO user's current physical street address. This should be a physical address, not a PO Box used for mailing purposes.
`physicalAddressCity`stringThe city associated with the SSO user's current physical street address.
`physicalAddressState`stringThe state associated with the SSO user's current physical street address.
`physicalAddressZip`stringThe 5 digit zip code associated with the SSO user's current physical street address.
`physicalAddressCountry`stringThe 2 digit ISO country code associated with the SSO user's current physical street address. This value must be `US`.
`authToken`*stringAn authorization token Blend can use to retrieve additional information regarding the SSO user from your APIs, such as their bank accounts data. Typically this is an OAuth token which authorizes Blend to access your APIs on behalf of the SSO user.
  • The `authToken` supports Blend functionality not in scope of a Consumer SSO implementation. If you are implementing Consumer SSO, you can safely ignore this field.

Omitted/Malformed Attribute Behavior

Blend ignores omitted or malformed attributes

### Specify your user attributes in the assertion's attribute statement.



## Errors

If any required parameters are missing or invalid, the authentication request will fail.