[{"data":1,"prerenderedAt":2077},["ShallowReactive",2],{"docs-\u002Fdocs\u002Fadmin\u002Fsso\u002Fsaml\u002F":3,"featureCatalog":1230,"docs-nav":1625},{"id":4,"title":5,"body":6,"description":19,"extension":1218,"layout":1219,"meta":1220,"navGroup":1219,"navGroupOrder":1219,"navOrder":1219,"navTitle":1221,"navigation":1222,"originalPath":1223,"path":1224,"redirect":1219,"seo":1225,"stem":1226,"updated":1227,"version":1228,"__hash__":1229},"docs\u002Fdocs\u002Fadmin\u002Fsso\u002Fsaml.md","Configuring SAML based Single Sign-On",{"type":7,"value":8,"toc":1184},"minimark",[9,13,20,28,31,36,39,53,56,82,85,88,99,102,119,122,125,128,133,136,140,143,147,182,193,197,200,203,206,209,245,249,252,255,263,267,276,280,283,290,293,296,299,306,309,345,349,352,366,369,391,397,400,417,421,424,427,446,468,471,474,478,485,496,500,503,506,510,516,524,527,542,545,549,552,584,587,595,598,662,665,795,800,807,813,816,819,826,832,835,881,890,893,905,951,954,961,964,970,973,987,1001,1011,1014,1020,1033,1036,1039,1042,1063,1066,1075,1078,1094,1097,1100,1107,1110,1141,1144,1147],[10,11,5],"h1",{"id":12},"configuring-saml-based-single-sign-on",[14,15,16],"p",{},[17,18,19],"em",{},"This feature is only available on FlowFuse Cloud and self-hosted Enterprise licensed instances of FlowFuse.",[14,21,22,23,27],{},"The SSO Configurations are managed by the platform Administrator under the\n",[24,25,26],"code",{},"Admin Settings > Settings > SSO"," section.",[14,29,30],{},"To fully configure SAML SSO, you will need to generate a configuration in FlowFuse,\nprovide some of the generated values to your Identity Provider, and copy back some\nvalues they provide.",[32,33,35],"h2",{"id":34},"configuring-sso-on-flowfuse-cloud","Configuring SSO on FlowFuse Cloud",[14,37,38],{},"Configuring SSO on FlowFuse Cloud requires co-ordinating tasks between the customer and\nFlowFuse Cloud administrators.",[14,40,41],{},[42,43,44,45,52],"strong",{},"All changes must be made via a ",[46,47,51],"a",{"href":48,"rel":49},"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002FCloudProject\u002Fissues\u002Fnew?assignees=&labels=change-request&projects=&template=change-request.yml&title=Change%3A+",[50],"nofollow","Production Change Request"," in the CloudProject repository - even if you are actioning it directly.",[14,54,55],{},"When a customer requests SSO to be setup for their users, we require the following information:",[57,58,59,67,76,79],"ol",{},[60,61,62,63,66],"li",{},"Confirm the customer's entitlement for SSO enablement. It is only available to ",[17,64,65],{},"Enterprise"," tier customers.",[60,68,69,70,75],{},"The email domain that will be covered by the configuration. Note that each SSO configuration can only be applied to a single domain. If a customer has multiple domains, each one will require its own SSO configuration. ",[46,71,74],{"href":72,"rel":73},"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fflowfuse\u002Fissues\u002F5011",[50],"Issue #5011"," has been raised to make this more flexible in the future.",[60,77,78],{},"Whether it is SAML or LDAP based SSO",[60,80,81],{},"What Identify Provider they are using for their SSO.",[14,83,84],{},"Once this information has been provided, create a Change Request issue in the CloudProject repository recording this information.",[14,86,87],{},"We can then create a draft SSO configuration in the Admin\u002FSettings\u002FSSO section. The configuration should not be marked as active yet.",[14,89,90,91,94,95,98],{},"From the draft configuration, the values of ",[24,92,93],{},"ACS URL"," and ",[24,96,97],{},"Entity ID \u002F Issuer"," can be given to the customer. These values will be required by their Identify Provider. Refer to the provider-specific documentation for how those values get applied.",[14,100,101],{},"In return, the customer then needs to provide:",[57,103,104,109,114],{},[60,105,106],{},[24,107,108],{},"Identity Provider Single Sign-On URL",[60,110,111],{},[24,112,113],{},"Identity Provider Issuer ID \u002F URL",[60,115,116],{},[24,117,118],{},"X.509 Certificate Public Key",[14,120,121],{},"Again, refer to the provider-specific documentation for where to find these values as each provider has its own terminology.",[14,123,124],{},"These values should be applied to the draft SSO configuration in FlowFuse Cloud. The configuration can then be marked as active.",[14,126,127],{},"It is recommended to do this final step whilst on a call with the customer so they can test the setup in real time.",[129,130,132],"h3",{"id":131},"common-issues","Common Issues",[14,134,135],{},"Aside from navigating the mismatched terminology between services providers, the most common issue we hit is where a login attempt fails and 'Invalid Document Signature' is shown in FlowFuse logs. This is because we expect both the SAML Assertions and Responses to be signed by the public certificate. The default configuration for many providers is to only sign the assertions - check the provider-specific documentation for the appropriate option to enable to address this.",[32,137,139],{"id":138},"configuring-sso","Configuring SSO",[14,141,142],{},"The following instructions give more details information on how to setup SSO.",[129,144,146],{"id":145},"create-a-sso-configuration","Create a SSO Configuration",[57,148,149,160,163,174],{},[60,150,151,152,155],{},"Click 'Create SSO Configuration' to create a new config",[153,154],"br",{},[156,157],"img",{"alt":158,"src":159},"","\u002Fdocs\u002Fadmin\u002Fsso\u002Fimages\u002Fcreate-sso-config.png",[60,161,162],{},"Give the configuration a name to help identify it, and provide the email domain\nname this configuration should apply to. Ensure the SAML option is selected - this\ncannot be changed after the configuration is created.",[60,164,165,166,168,169,171],{},"Click 'Create configuration'",[153,167],{},"At this point, the configuration has been created and metadata generated for the\nconfiguration, but it is not active.",[153,170],{},[156,172],{"alt":158,"src":173},"\u002Fdocs\u002Fadmin\u002Fsso\u002Fimages\u002Fedit-sso-config.png",[60,175,176,177,94,179,181],{},"Copy the ",[24,178,93],{},[24,180,97],{}," values as you will need to configure\nyour Identity Provider with these values.",[14,183,184,185,188,189,192],{},"You can save the configuration at any time by clicking the ",[24,186,187],{},"Update configuration","\nbutton. The configuration will only be enabled when you tick the ",[24,190,191],{},"active"," checkbox\nand save the changes.",[129,194,196],{"id":195},"configure-your-identify-provider","Configure your Identify Provider",[14,198,199],{},"Every Identity Provider uses slightly different terminology and varies what\ninformation they require and what they provide. This can make it a tricky task\nto complete.",[14,201,202],{},"We provide specific guides for the providers we have verified below.",[14,204,205],{},"If you have a working configuration for a provider not listed here, please do\nshare the details so we can add them to the list.",[14,207,208],{},"The general points are:",[57,210,211,234],{},[60,212,213,214],{},"Your Identity Provider will supply you with some of the following values that\nshould be entered into your FlowFuse SAML SSO Configuration:",[215,216,217,223,228],"ul",{},[60,218,219,222],{},[24,220,221],{},"Single Sign-On URL"," - also referred to as 'SAML Endpoint', 'Login URL' or 'IdP SSO URL'.",[60,224,225],{},[24,226,227],{},"Issuer ID \u002F URL",[60,229,230,233],{},[24,231,232],{},"X.509 Certification Public Key"," - the public key of a certificate used to sign\nSAML requests.",[60,235,236,237,240,241,244],{},"Configure the ",[24,238,239],{},"NameID"," SAML option to be ",[24,242,243],{},"EmailAddress"," and have it return the email\nof the user logging in. This is how FlowFuse will verify they are a known user\non the platform.",[129,246,248],{"id":247},"session-length-overrides","Session Length Overrides",[14,250,251],{},"Each SSO configuration can override the platform default Max Session life an Max Session Idle time.",[14,253,254],{},"These are Controlled by the \"Custom Session Expiry (hours)\" and \"Custom Session Idle Time (hours)\" respectively.",[14,256,257,261],{},[156,258],{"alt":259,"src":260},"Settings for Custom Session lifetime","\u002Fdocs\u002Fadmin\u002Fsso\u002Fimages\u002Fedit-sso-custom-session.png",[17,262,259],{},[129,264,266],{"id":265},"enable-your-saml-sso-configuration","Enable your SAML SSO Configuration",[14,268,269,270,272,273,275],{},"Once you have setup both sides of the configuration you can enable it for use\nby ticking the ",[24,271,191],{}," checkbox and clicking ",[24,274,187],{},".",[32,277,279],{"id":278},"creating-new-users","Creating new users",[14,281,282],{},"With FlowFuse 2.7, the SSO Configuration now includes an option to automatically\nregister users who sign in via the configuration.",[14,284,285,286,289],{},"This option is not enabled by default, but can be enabled but selecting the ",[24,287,288],{},"Allow Provisioning of New Users on first login","\noption in the SOO configuration.",[14,291,292],{},"When creating the user, the platform will use information provided by the SAML provider\nto create the username. The user will be directed to their settings page where they\ncan modify their user details to their preferred values.",[14,294,295],{},"## Managing Team Membership with SAML Groups",[14,297,298],{},"Some SAML providers allow user group information to be shared as part of the sign-in process.\nWhen properly configured, this can be used to manage what FlowFuse teams a user has access to.",[14,300,301,302,305],{},"To enable this option, select the ",[24,303,304],{},"Manage roles using group assertions"," in the SSO configuration.",[14,307,308],{},"The following configuration options should then be set:",[215,310,311,321],{},[60,312,313,316,317,320],{},[24,314,315],{},"Group Assertion Name"," - this is used to identify the group membership information in the response\nsent by the Identity Provider. It defaults to ",[24,318,319],{},"ff-roles"," but can be customised if the Identify Provider\nrequires it.",[60,322,323,326,327],{},[24,324,325],{},"Team Scope"," - this determines what teams can be managed using this configuration. There are two options:\n",[215,328,329,335],{},[60,330,331,334],{},[24,332,333],{},"Apply to all teams"," - this will allow the SAML groups to manage all teams on the platform. This is\nsuitable for a self-hosted installation of FlowFuse with a single SSO configuration for all users on\nthe platform.",[60,336,337,340,341,344],{},[24,338,339],{},"Apply to selected teams"," - this will restrict what teams can be managed to the provided list. This\nis suitable for shared-tenancy platforms with multiple SSO configurations for different groups of users,\nsuch as FlowFuse Cloud.\nWhen this option is selected, an additional option is available - ",[24,342,343],{},"Allow users to be in other teams",". This\nwill allow users who sign-in via this SSO configuration to be members of teams not in the list above.\nTheir membership of those teams will not be managed by the SSO groups.\nIf that option is disabled, then the user will be removed from any teams not in the list above.",[129,346,348],{"id":347},"saml-groups-configuration","SAML Groups configuration",[14,350,351],{},"A user's team membership is managed by what groups they are in. When the user logs in, the SAML provider\nmust be configured to provide a list of groups they are a member of as a SAML assertion.",[14,353,354,355,358,359,362,363,275],{},"The group name is used to identify a team, using its slug property, and the user's role in the team.\nThe name must take the form ",[24,356,357],{},"ff-\u003Cteam>-\u003Crole>",". For example, the group ",[24,360,361],{},"ff-development-owner"," will\ncontainer the owners of the team ",[24,364,365],{},"development",[14,367,368],{},"The valid roles for a user in a team are:",[215,370,371,376,381,386],{},[60,372,373],{},[24,374,375],{},"owner",[60,377,378],{},[24,379,380],{},"member",[60,382,383],{},[24,384,385],{},"viewer",[60,387,388],{},[24,389,390],{},"dashboard",[14,392,393,396],{},[17,394,395],{},"Note",": this uses the team slug property to identify the team. This has been chosen to simplify managing\nthe groups in the SAML Provider - rather than using the team's id. However, a team's slug can be changed\nby a team owner. Doing so will break the link between the group and the team membership - so should only\nbe done with care.",[14,398,399],{},"An optional prefix and suffix can be include in the group name to support SAML providers that have existing naming policies. The SSO configuration can be configured with the lengths of these values so they will be stripped off before the group name is validated.",[14,401,402,403,406,407,410,411,414,415,275],{},"For example, if an organisation requires all groups to begin with ",[24,404,405],{},"acme-org-",", a prefix length of ",[24,408,409],{},"9"," can be set and the group ",[24,412,413],{},"acme-org-ff-development-owner"," will be handled as ",[24,416,361],{},[129,418,420],{"id":419},"application-level-groups","Application Level Groups",[14,422,423],{},"In addition to being able to add Users to Teams using groups, Role overrides for specific Applications within those groups can also be controlled.",[14,425,426],{},"The User must have a membership of the Team the Application belongs to for an Application override to take effect. If the User is not a member of that Team, the override is ignored.",[14,428,429,430,433,434,437,438,441,442,445],{},"Groups for Application overrides use a similar pattern to Team Groups and use the same prefix and suffix length modifiers. They take the form ",[24,431,432],{},"ff-\u003Cteam>[\u003Capplication>]-\u003Crole>",", where ",[24,435,436],{},"\u003Capplication>"," can be the Application name or id and ",[24,439,440],{},"\u003Crole>"," must be one of the valid roles listed above, but can also be ",[24,443,444],{},"none"," to remove access from an Application within the Team. Any unrecognised role is ignored.",[14,447,448,449,451,452,455,456,458,459,461,462,464,465,275],{},"For example, given a Team called ",[24,450,365],{}," and an Application called ",[24,453,454],{},"test",", owner-level access to the Team would be granted by membership of a group named ",[24,457,361],{},", and an override to ",[24,460,385],{}," for the Application ",[24,463,454],{}," would be granted by ",[24,466,467],{},"ff-development[test]-viewer",[14,469,470],{},"If multiple groups grant different roles for the same Application, the highest role is applied.",[14,472,473],{},"Application overrides applied this way are managed by the SSO provider: they cannot be edited in the FlowFuse UI, and if the corresponding group is removed the override is cleared the next time the User logs in.",[32,475,477],{"id":476},"managing-admin-users","Managing Admin users",[14,479,480,481,484],{},"The SSO Configuration can be configured to manage the admin users of the platform by enabling the\n",[24,482,483],{},"Manage Admin roles using group assertions"," option. Once enabled, the name of a group can be provided\nthat will be used to identify whether a user is an admin or not.",[14,486,487,488,491,492,495],{},"*",[17,489,490],{},"Note:"," the platform will refuse to remove the admin flag from a user if they are the only admin\non the platform. It is ",[17,493,494],{},"strongly"," recommended to have an admin user on the system that is not\nmanaged via SSO to ensure continued access in case of any issues with the SSO provider.",[32,497,499],{"id":498},"direct-sso-login","Direct SSO Login",[14,501,502],{},"For Self Hosted users there is an option in the Admin Settings to enable buttons on the login page for each active SAML SSO provider.",[14,504,505],{},"These buttons will redirect to the SSO provider rather than requiring users to enter and email address in the username field to select the correct provider.",[32,507,509],{"id":508},"forcing-all-users-to-use-sso","Forcing All Users to Use SSO",[14,511,512,513,275],{},"For self-hosted installations that need to ensure no user can bypass SSO, there is an option in ",[42,514,515],{},"Admin Settings > Settings > SSO > Force all logins for non-admin users via a single SAML SSO provider",[14,517,518,522],{},[156,519],{"alt":520,"src":521},"SSO settings page showing the option to force all non-admin users to log in via a single SAML SSO provider","\u002Fdocs\u002Fadmin\u002Fsso\u002Fimages\u002Fforce-sso.png",[17,523,520],{},[14,525,526],{},"When this option is enabled:",[215,528,529,532,535],{},[60,530,531],{},"All users are redirected to the configured SSO provider at login, regardless of their email domain",[60,533,534],{},"The email and password login form is no longer presented as a fallback option",[60,536,537,538,541],{},"Admin users can bypass SSO by accessing ",[24,539,540],{},"\u002Fadmin"," routes",[14,543,544],{},"This is intended for organisations running a single identity provider across the entire platform, where per-domain SSO configuration is not sufficient to cover all users.",[32,546,548],{"id":547},"providers","Providers",[14,550,551],{},"The following is a non-exhaustive list of the providers that are known to work\nwith FlowFuse SAML SSO.",[215,553,554,560,566,572,578],{},[60,555,556],{},[46,557,559],{"href":558},"#microsoft-entra","Microsoft Entra",[60,561,562],{},[46,563,565],{"href":564},"#google-workspace","Google Workspace",[60,567,568],{},[46,569,571],{"href":570},"#onelogin","OneLogin",[60,573,574],{},[46,575,577],{"href":576},"#okta","Okta",[60,579,580],{},[46,581,583],{"href":582},"#keycloak","Keycloak",[129,585,559],{"id":586},"microsoft-entra",[14,588,589,590,275],{},"Microsoft provide a guide for creating a custom SAML Application ",[46,591,594],{"href":592,"rel":593},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fentra\u002Fidentity\u002Fenterprise-apps\u002Fadd-application-portal",[50],"here",[14,596,597],{},"The following tables map the Entra terminology to the FlowFuse settings.",[599,600,601,614],"table",{},[602,603,604],"thead",{},[605,606,607,611],"tr",{},[608,609,610],"th",{},"FlowFuse Setting",[608,612,613],{},"Entra Setting",[615,616,617,629,640,651],"tbody",{},[605,618,619,624],{},[620,621,622],"td",{},[24,623,93],{},[620,625,626],{},[24,627,628],{},"Reply URL (Assertion Consumer Service URL)",[605,630,631,635],{},[620,632,633],{},[24,634,113],{},[620,636,637],{},[24,638,639],{},"Microsoft Entra Identifier",[605,641,642,646],{},[620,643,644],{},[24,645,108],{},[620,647,648],{},[24,649,650],{},"Login URL",[605,652,653,657],{},[620,654,655],{},[24,656,118],{},[620,658,659],{},[24,660,661],{},"Certificate (Base64)",[14,663,664],{},"Follow these steps to properly configure SAML SSO for Microsoft Entra:",[57,666,667,675,741],{},[60,668,669,670],{},"In FlowFuse:\n",[57,671,672],{},[60,673,674],{},"Create a draft SSO configuration in FlowFuse with the appropriate email domain",[60,676,677,678],{},"In Entra:\n",[57,679,680,683,705,719,730],{},[60,681,682],{},"Create a SAML application - use the guide linked above for more information",[60,684,685,686],{},"Copy the following values from the FlowFuse SSO configuration into the corresponding Entra configuration:\n",[57,687,688,697],{},[60,689,690,691,694,695],{},"Set ",[24,692,693],{},"Reply URL"," to the value of ",[24,696,93],{},[60,698,690,699,694,702],{},[24,700,701],{},"Identifier (Entity ID)",[24,703,704],{},"Entity ID\u002FIssuer",[60,706,707,708,711,712,715,716,275],{},"Within the ",[24,709,710],{},"SAML Signing Certificate"," configuration, the ",[24,713,714],{},"Signing Option"," must be set to ",[24,717,718],{},"Sign SAML response and assertion",[60,720,721,722,725,726,729],{},"The ",[24,723,724],{},"Unique User Identifier (Name ID)"," claim must be configured to return the value of the ",[24,727,728],{},"user.mail"," source attribute.",[60,731,732,733,736,737,740],{},"Download the ",[24,734,735],{},"Federation Metadata XML"," file from the ",[24,738,739],{},"SAML Certificates"," section of the Entra application.",[60,742,669,743],{},[57,744,745],{},[60,746,747,748],{},"From the metadata XML file, copy the follow properties into the FlowFuse SSO configuration:\n",[57,749,750,766,779],{},[60,751,690,752,754,755,758,759,762,763,275],{},[24,753,108],{}," to the value of the ",[24,756,757],{},"Location"," attribute of the ",[24,760,761],{},"\u003CSingleSignOnService>"," tag. This should look like ",[24,764,765],{},"https:\u002F\u002Flogin.microsoftonline.com\u002F\u003Capp-id>\u002Fsaml2",[60,767,690,768,754,770,758,773,762,776],{},[24,769,113],{},[24,771,772],{},"entityID",[24,774,775],{},"\u003CEntityDescriptor>",[24,777,778],{},"https:\u002F\u002Fsts.windows.net\u002F\u003Capp-id>\u002F",[60,780,690,781,754,783,786,787,790,791,794],{},[24,782,118],{},[24,784,785],{},"\u003Cds:X509Certificate>"," tag. This does ",[17,788,789],{},"not"," need to have the ",[24,792,793],{},"-----BEGIN CERTIFICATE-----\u002F-----END CERTIFICATE-----"," wrapper.",[796,797,799],"h4",{"id":798},"group-membership-configuration","Group Membership Configuration",[14,801,802,803,806],{},"By default, when enabled, Entra will share group assertions under the name ",[24,804,805],{},"http:\u002F\u002Fschemas.microsoft.com\u002Fws\u002F2008\u002F06\u002Fidentity\u002Fclaims\u002Fgroups"," and provides the groups as a list of object ids.",[14,808,809,810,812],{},"Either the ",[24,811,315],{}," should be set to this name, or Entra configured to use a custom\nassertion name that matches the FlowFuse SSO Configuration value.",[14,814,815],{},"Entra must also be configured to return group names rather than object ids.",[129,817,565],{"id":818},"google-workspace",[14,820,821,822,275],{},"Google provide a guide for creating a custom SAML Application ",[46,823,594],{"href":824,"rel":825},"https:\u002F\u002Fsupport.google.com\u002Fa\u002Fanswer\u002F6087519?hl=en",[50],[14,827,828,829,275],{},"Google Workspace only supports HTTPS-based SSO URLs. You cannot use it when developing\nlocally using ",[24,830,831],{},"http:\u002F\u002Flocalhost:3000",[14,833,834],{},"The following table maps the Google Workspace terminology to the FlowFuse settings.",[599,836,837,846],{},[602,838,839],{},[605,840,841,843],{},[608,842,610],{},[608,844,845],{},"Google Workspace Setting",[615,847,848,859,870],{},[605,849,850,854],{},[620,851,852],{},[24,853,108],{},[620,855,856],{},[24,857,858],{},"SSO URL",[605,860,861,865],{},[620,862,863],{},[24,864,113],{},[620,866,867],{},[24,868,869],{},"Entity ID",[605,871,872,876],{},[620,873,874],{},[24,875,118],{},[620,877,878],{},[24,879,880],{},"Certificate",[14,882,707,883,711,886,889],{},[24,884,885],{},"Service provider details",[24,887,888],{},"Signed response"," option must be enabled.",[129,891,571],{"id":892},"onelogin",[14,894,895,896,901,902,275],{},"Follow ",[46,897,900],{"href":898,"rel":899},"https:\u002F\u002Fonelogin.service-now.com\u002Fsupport?id=kb_article&sys_id=93f95543db109700d5505eea4b96198f",[50],"this guide","\nto create a ",[24,903,904],{},"OneLogin SAML Test Connector",[599,906,907,916],{},[602,908,909],{},[605,910,911,913],{},[608,912,610],{},[608,914,915],{},"OneLogin Setting",[615,917,918,929,940],{},[605,919,920,924],{},[620,921,922],{},[24,923,108],{},[620,925,926],{},[24,927,928],{},"SAML 2.0 Endpoint (HTTP)",[605,930,931,935],{},[620,932,933],{},[24,934,113],{},[620,936,937],{},[24,938,939],{},"Issuer URL",[605,941,942,946],{},[620,943,944],{},[24,945,118],{},[620,947,948],{},[24,949,950],{},"X.509 Certificate",[129,952,577],{"id":953},"okta",[14,955,956,957,960],{},"Within your Okta Admin dashboard, browse the App Integration catalog and add a new\ninstance of the ",[24,958,959],{},"SAML Service Provider"," integration.",[14,962,963],{},"On the Sign-On Options section, ensure SAML 2.0 is selected. Below that section\nyou will see a notice saying:",[965,966,967],"blockquote",{},[14,968,969],{},"SAML 2.0 in not configured until you complete the setup instructions.",[14,971,972],{},"Click the 'View setup instructions' button to open the page in a new window.",[14,974,975,976,979,980,94,983,986],{},"Follow the instructions on that - copying the ",[24,977,978],{},"Identity Provider Issuer",",\n",[24,981,982],{},"Identity Provider HTTP POST URL",[24,984,985],{},"Identity Provider Certificate"," values\ninto the FlowFuse SSO configuration.",[14,988,989,990,993,994,94,997,1000],{},"Back on the Okta SAML Application configuration page, under the ",[24,991,992],{},"Advanced Sign-on Settings","\nsection enter the ",[24,995,996],{},"Assertion Consumer Service URL",[24,998,999],{},"Service Provider Entity Id","\nfrom the FlowFuse SSO configuration.",[14,1002,1003,1004,1007,1008,275],{},"Under ",[24,1005,1006],{},"Credential Details"," section, change the Application username format to ",[24,1009,1010],{},"Email",[796,1012,799],{"id":1013},"group-membership-configuration-1",[14,1015,1016,1017,275],{},"To configure Okta to return Group assertions, edit the Settings of the SAML Service Provider's\nSAML 2.0 configuration. Expand the 'Attributes' section and add a ",[24,1018,1019],{},"Group Attribute Statement",[14,1021,1022,1023,1025,1026,1028,1029,1032],{},"The name must match the ",[24,1024,315],{}," in the FlowFuse SSO configuration (default: ",[24,1027,319],{},").\nYou can optionally add a filter of ",[24,1030,1031],{},"ff-"," so that it only returns groups used by FlowFuse.",[129,1034,583],{"id":1035},"keycloak",[14,1037,1038],{},"Within your Keycloak Admin Console, create a new Client with the following settings:",[14,1040,1041],{},"Under the General Settings:",[215,1043,1044,1053],{},[60,1045,690,1046,1049,1050],{},[24,1047,1048],{},"Client type"," to ",[24,1051,1052],{},"SAML",[60,1054,1055,1056,1059,1060,1062],{},"Set the ",[24,1057,1058],{},"Client ID"," to the ",[24,1061,97],{}," value from the FlowFuse SSO configuration.",[14,1064,1065],{},"Under the Login Settings:",[215,1067,1068],{},[60,1069,690,1070,1059,1073,1062],{},[24,1071,1072],{},"Valid redirect URIs",[24,1074,93],{},[14,1076,1077],{},"Once created and you are shown the full client configuration, make the following additional changes:",[215,1079,1080,1088],{},[60,1081,690,1082,1049,1085],{},[24,1083,1084],{},"Name ID format",[24,1086,1087],{},"email",[60,1089,1090,1091],{},"Under the 'Keys' tab, turn off ",[24,1092,1093],{},"Client signature required",[14,1095,1096],{},"Save the changes.",[14,1098,1099],{},"Next, select the 'Download adapter config' option under the 'Action' dropdown menu. Select the\n'Mod Auth Mellon files' format and click Download.",[14,1101,1102,1103,1106],{},"This will download a zip file. Extract the zip and open the ",[24,1104,1105],{},"idp-metadata.xml"," file in a text editor.",[14,1108,1109],{},"The final task is to copy some of the contents of the XML file into the FlowFuse SSO configuration.",[215,1111,1112,1121,1132],{},[60,1113,1114,1115,1117,1118,1120],{},"Copy the value of the ",[24,1116,772],{}," attribute into the ",[24,1119,113],{}," property",[60,1122,1123,1124,1127,1128,1117,1130,1120],{},"Find one of the ",[24,1125,1126],{},"md:SingleSignOnService"," tags and copy the value of its ",[24,1129,757],{},[24,1131,108],{},[60,1133,1134,1135,1138,1139,1120],{},"Copy the contents of the ",[24,1136,1137],{},"ds:X509Certificate"," tag into the ",[24,1140,118],{},[796,1142,799],{"id":1143},"group-membership-configuration-2",[14,1145,1146],{},"In Keycloak and the Realm setup with FlowFuse as a client:",[215,1148,1149,1152,1157,1160,1163,1166,1172,1175,1178,1181],{},[60,1150,1151],{},"Create a new \"Client Scope\"",[60,1153,1154,1155],{},"Give it a name and ensure the \"Protocol\" is ",[24,1156,1052],{},[60,1158,1159],{},"After saving the scope, select the \"Mappers\" tab",[60,1161,1162],{},"\"Add mapper\" and pick \"By configuration\"",[60,1164,1165],{},"Select \"Group list\" from the options",[60,1167,1168,1169,1171],{},"Give it a name and set \"Group attribute name\" to ",[24,1170,319],{}," (this must match the value configured in FlowFuse, default 'ff-roles')",[60,1173,1174],{},"Enable 'Single Group Attribute'",[60,1176,1177],{},"Ensure that \"Full group path\" is unchecked",[60,1179,1180],{},"Save and return to the \"Clients\" list and select your FlowFuse Client created earlier",[60,1182,1183],{},"Under \"Client scopes\", use the \"Add client scope\" button to add the new scope",{"title":158,"searchDepth":1185,"depth":1185,"links":1186},4,[1187,1192,1198,1202,1203,1204,1205],{"id":34,"depth":1188,"text":35,"children":1189},2,[1190],{"id":131,"depth":1191,"text":132},3,{"id":138,"depth":1188,"text":139,"children":1193},[1194,1195,1196,1197],{"id":145,"depth":1191,"text":146},{"id":195,"depth":1191,"text":196},{"id":247,"depth":1191,"text":248},{"id":265,"depth":1191,"text":266},{"id":278,"depth":1188,"text":279,"children":1199},[1200,1201],{"id":347,"depth":1191,"text":348},{"id":419,"depth":1191,"text":420},{"id":476,"depth":1188,"text":477},{"id":498,"depth":1188,"text":499},{"id":508,"depth":1188,"text":509},{"id":547,"depth":1188,"text":548,"children":1206},[1207,1210,1211,1212,1215],{"id":586,"depth":1191,"text":559,"children":1208},[1209],{"id":798,"depth":1185,"text":799},{"id":818,"depth":1191,"text":565},{"id":892,"depth":1191,"text":571},{"id":953,"depth":1191,"text":577,"children":1213},[1214],{"id":1013,"depth":1185,"text":799},{"id":1035,"depth":1191,"text":583,"children":1216},[1217],{"id":1143,"depth":1185,"text":799},"md",null,{},"SAML SSO",true,"admin\u002Fsso\u002Fsaml.md","\u002Fdocs\u002Fadmin\u002Fsso\u002Fsaml",{"title":5,"description":19},"docs\u002Fadmin\u002Fsso\u002Fsaml","2026-07-17 13:36:25 +0000","2.33.2","8EbocbRAiLysSxHaHZUAkSfeQk-C7wF7FQ6-gK0urN4",{"id":1231,"extension":1232,"meta":1233,"sections":1234,"stem":1623,"__hash__":1624},"featureCatalog\u002Ffeature-catalog.yml","yml",{},[1235,1286,1387,1449,1526,1605],{"id":1236,"title":1237,"features":1238},"ai-automation","AI & Automation",[1239,1249,1259,1269,1275,1281],{"id":1240,"title":1241,"description":1242,"docsLink":1243,"changelog":1244,"tiers":1248},"flowfuse-expert-ai","FlowFuse Expert AI","Build industrial apps with agents, and query the state of the factory with an agent. Adapt your current hardware and machines so agentic work can be done against them, without ripping and replacing what's already on the plant floor.","\u002Fdocs\u002Fuser\u002Fexpert\u002F",[1245],{"url":1246,"release":1247},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-update-banner\u002F","2.28",{"edge":1222,"hub":1222,"fleet":1222},{"id":1250,"title":1251,"description":1252,"docsLink":1253,"changelog":1254,"subfeature":1222,"showOnPricing":1257,"tiers":1258},"flowfuse-expert-support-mode","Support Mode","Chat-based assistance for FlowFuse and Node-RED, including Node-RED instance management through natural language.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F#support-mode",[1255],{"url":1256,"release":1247},"\u002Fchangelog\u002F2026\u002F02\u002Fff-expert-debug-log-context\u002F",false,{"edge":1222,"hub":1222,"fleet":1222},{"id":1260,"title":1261,"description":1262,"docsLink":1263,"changelog":1264,"subfeature":1222,"showOnPricing":1257,"tiers":1268},"flowfuse-expert-application-building","Application Building","Describe what you want to build and FlowFuse Expert assembles it on your workspace, adding tabs, wiring nodes, and configuring properties.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F",[1265],{"url":1266,"release":1267},"\u002Fchangelog\u002F2026\u002F05\u002Fexpert-application-building\u002F","2.30",{"edge":1222,"hub":1222,"fleet":1222},{"id":1270,"title":1271,"description":1272,"docsLink":1273,"subfeature":1222,"beta":1222,"showOnPricing":1257,"tiers":1274},"flowfuse-expert-insights-mode","Insights Mode","Connects FlowFuse Expert to MCP servers in your Node-RED instances, enabling real-time data queries and actions through a single chat interface.","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat\u002F#insights-mode",{"edge":1222,"hub":1222,"fleet":1222},{"id":1276,"title":1277,"description":1278,"docsLink":1279,"tiers":1280},"mcp-servers","Agentic Operations","Expose your Node-RED flows as tools an AI agent can call directly, so agents can query the state of the factory or trigger actions without custom integration work.","\u002Fnode-red\u002Fflowfuse\u002Fmcp\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1282,"title":1283,"description":1284,"tiers":1285},"onnx-integration","ONNX Integration","Run trained machine learning models directly in your flows, including on edge hardware, without sending data out to an external inference service.",{"edge":1222,"hub":1222,"fleet":1222},{"id":1287,"title":1288,"features":1289},"build","Build",[1290,1296,1302,1312,1318,1324,1328,1334,1340,1348,1354,1358,1362,1371,1379],{"id":1291,"title":1292,"description":1293,"docsLink":1294,"tiers":1295},"edge-development","Edge Development","Develop and test Node-RED flows directly on edge devices with a remote editor proxy.","\u002Fdocs\u002Fdevice-agent\u002Fquickstart\u002F",{"edge":1222,"hub":1257,"fleet":1222},{"id":1297,"title":1298,"description":1299,"docsLink":1300,"tiers":1301},"private-npm-registry","Custom Node-RED Nodes","Create and manage your own private npm registry for Node-RED nodes, so you can share custom nodes across your team and devices without publishing them publicly.","\u002Fdocs\u002Fuser\u002Fcustom-npm-packages\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1303,"title":1304,"description":1305,"docsLink":1306,"changelog":1307,"tiers":1311},"flowfuse-tables","FlowFuse Tables","A managed PostgreSQL database for every application, so you can store and query structured data without standing up and maintaining your own database.","\u002Fdocs\u002Fuser\u002Fff-tables\u002F",[1308],{"url":1309,"release":1310},"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-tables-automation\u002F","2.33",{"edge":1222,"hub":1222,"fleet":1222},{"id":1313,"title":1314,"description":1315,"docsLink":1316,"tiers":1317},"persistent-files","File Storage","Store and retrieve files from your Node-RED flows, with automatic replication and backup across your devices and hosted instances.","\u002Fdocs\u002Finstall\u002Ffile-storage\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1319,"title":1320,"description":1321,"docsLink":1322,"showOnPricing":1257,"tiers":1323},"persistent-context","Persistent Context","In-memory values defined in a Node-RED flow persist across project restarts and upgrades.","\u002Fdocs\u002Fuser\u002Fpersistent-context\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1325,"title":1326,"showOnPricing":1257,"tiers":1327},"static-assets","Static Assets",{"edge":1222,"hub":1222,"fleet":1222},{"id":1329,"title":1330,"description":1331,"docsLink":1332,"tiers":1333},"team-library","Team Library","Set up standard nodes and flows that can be shared with all team members across your organisation.","\u002Fdocs\u002Fuser\u002Fshared-library\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1335,"title":1336,"description":1337,"docsLink":1338,"tiers":1339},"personalised-multi-user-dashboards","Personalised Multi-User Dashboards","Build applications that provide unique data to each logged-in user using personalised multi-user dashboards.","https:\u002F\u002Fdashboard.flowfuse.com\u002Fuser\u002Fmulti-tenancy.html",{"edge":1222,"hub":1222,"fleet":1222},{"id":1341,"title":1342,"description":1343,"changelog":1344,"subfeature":1222,"showOnPricing":1257,"tiers":1347},"dashboards-view","Dashboards View","Browse and open every dashboard across your team from a dedicated Dashboards view, at both team and application level, without leaving FlowFuse.",[1345],{"url":1346,"release":1310},"\u002Fchangelog\u002F2026\u002F07\u002Fteam-and-application-dashboards\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1349,"title":1350,"description":1351,"docsLink":1352,"tiers":1353},"blueprints-converge","Blueprints","Ready-made starting points for your apps, from cross-team Converge templates to OT and IT specific blueprints.","\u002Fdocs\u002Fuser\u002Fconcepts\u002F#blueprint",{"edge":1222,"hub":1222,"fleet":1222},{"id":1355,"title":1356,"subfeature":1222,"showOnPricing":1257,"tiers":1357},"blueprints-ot-apps","Blueprints - OT APPS",{"edge":1222,"hub":1257,"fleet":1222},{"id":1359,"title":1360,"subfeature":1222,"showOnPricing":1257,"tiers":1361},"blueprints-it-apps","Blueprints - IT APPS",{"edge":1257,"hub":1222,"fleet":1257},{"id":1363,"title":1364,"description":1365,"changelog":1366,"showOnPricing":1257,"tiers":1370},"immersive-editor-snapshots","Snapshot Details in Immersive Editor","View and manage snapshot details directly inside the immersive editor without leaving your editing session.",[1367],{"url":1368,"release":1369},"\u002Fchangelog\u002F2026\u002F03\u002Fsnapshot-detail-modal-immersive-editor\u002F","2.29",{"edge":1222,"hub":1222,"fleet":1222},{"id":1372,"title":1373,"description":1374,"changelog":1375,"showOnPricing":1257,"tiers":1378},"immersive-editor-drawer","Customisable Immersive Editor Drawer","Pin, move, resize, or full-screen the immersive editor drawer. Your preferences are remembered between sessions.",[1376],{"url":1377,"release":1267},"\u002Fchangelog\u002F2026\u002F04\u002Fimmersive-editor-drawer\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1380,"title":1381,"description":1382,"changelog":1383,"showOnPricing":1257,"tiers":1386},"embedded-editor-tab-title","Embedded Editor Browser Tab Title","The browser tab title updates to reflect the active Node-RED canvas tab when working in the embedded editor.",[1384],{"url":1385,"release":1369},"\u002Fchangelog\u002F2026\u002F03\u002Fembedded-editor-tab-title\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1388,"title":1389,"features":1390},"deploy","Deploy",[1391,1397,1406,1412,1418,1424,1430,1436,1441],{"id":1392,"title":1393,"description":1394,"docsLink":1395,"tiers":1396},"hosted-instances","Cloud Instances","Run Node-RED instances managed and hosted by FlowFuse.","\u002Fdocs\u002Fuser\u002Fintroduction\u002F#creating-a-node-red-instance",{"edge":1222,"hub":1222,"fleet":1222},{"id":1398,"title":1399,"description":1400,"docsLink":1401,"changelog":1402,"tiers":1405},"edge-devices","Edge Instances","Deploy and mange your Node-RED instances on edge PLCs and gateways, with full visibility and control from the cloud.","\u002Fdocs\u002Fdevice-agent\u002Fintroduction\u002F",[1403],{"url":1404,"release":1247},"\u002Fchangelog\u002F2026\u002F02\u002Fdevice-agent-nodejs-options\u002F",{"edge":1222,"hub":1257,"fleet":1222},{"id":1407,"title":1408,"description":1409,"docsLink":1410,"tiers":1411},"custom-hostnames","Custom Hostnames","Access your Node-RED application via your own domain name.","\u002Fdocs\u002Fuser\u002Fcustom-hostnames\u002F",{"edge":1257,"hub":1222,"fleet":1257},{"id":1413,"title":1414,"description":1415,"docsLink":1416,"tiers":1417},"mqtt-broker","MQTT Broker","Manage and create MQTT clients to transport data for efficient messaging and communication within your applications.","\u002Fdocs\u002Fuser\u002Fteambroker\u002F",{"edge":1222,"hub":1257,"fleet":1222},{"id":1419,"title":1420,"description":1421,"docsLink":1422,"showOnPricing":1257,"tiers":1423},"project-nodes","Project Nodes aka seamless project comms","FlowFuse Project Nodes enable the passing of data and messages between your Node-RED projects.","\u002Fdocs\u002Fuser\u002Fprojectnodes\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1425,"title":1426,"description":1427,"docsLink":1428,"tiers":1429},"devops-pipelines","DevOps Pipelines","Set up different environments for development, testing, and production Node-RED instances to support a full software delivery lifecycle.","\u002Fdocs\u002Fuser\u002Fdevops-pipelines\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1431,"title":1432,"description":1433,"docsLink":1434,"tiers":1435},"git-integration","Git Integration","Back up your flows to a remote Git repository through a DevOps Pipeline. Supports GitHub and Azure DevOps repositories.","\u002Fdocs\u002Fuser\u002Fdevops-pipelines\u002F#git-repository-stage",{"edge":1257,"hub":1222,"fleet":1257},{"id":1437,"title":1438,"description":1439,"docsLink":1434,"subfeature":1222,"showOnPricing":1257,"tiers":1440},"git-integration-github","GitHub","Push and pull snapshots to GitHub repositories through DevOps Pipeline Git Stages.",{"edge":1257,"hub":1222,"fleet":1257},{"id":1442,"title":1443,"description":1444,"docsLink":1434,"changelog":1445,"subfeature":1222,"showOnPricing":1257,"tiers":1448},"git-integration-azure","Azure DevOps","Push and pull snapshots to Azure DevOps repositories through DevOps Pipeline Git Stages.",[1446],{"url":1447,"release":1369},"\u002Fchangelog\u002F2026\u002F03\u002Fazure-dev-ops-gitops\u002F",{"edge":1257,"hub":1222,"fleet":1257},{"id":1450,"title":1451,"features":1452},"operate-maintain","Operate & Maintain",[1453,1459,1465,1470,1478,1482,1486,1491,1497,1503,1508,1514,1518,1522],{"id":1454,"title":1455,"description":1456,"docsLink":1457,"tiers":1458},"snapshots","Snapshots & Version History","Automatic snapshots on remote devices and hosted instances, plus a full version history timeline so you can roll back to any prior state.","\u002Fdocs\u002Fuser\u002Fsnapshots\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1460,"title":1461,"description":1462,"docsLink":1463,"subfeature":1222,"showOnPricing":1257,"tiers":1464},"auto-snapshot-remote","Auto Snapshot (Remote)","Automatically capture a snapshot every time a remote instance is deployed, so you always have a recoverable history of what was running on each device.","\u002Fdocs\u002Fuser\u002Fsnapshots\u002F#auto-snapshots",{"edge":1222,"hub":1222,"fleet":1222},{"id":1466,"title":1467,"description":1468,"docsLink":1463,"subfeature":1222,"showOnPricing":1257,"tiers":1469},"auto-snapshot-hosted","Auto Snapshot (Hosted)","Automatically capture a snapshot every time a hosted instance is deployed, so you always have a recoverable history of what was running.",{"edge":1222,"hub":1222,"fleet":1222},{"id":1471,"title":1472,"description":1473,"changelog":1474,"subfeature":1222,"showOnPricing":1257,"tiers":1477},"snapshot-comparison","Snapshot Comparison","Compare two snapshots side-by-side with a navigable diff view. Step through every changed, added, or deleted node and see property and code diffs.",[1475],{"url":1476,"release":1369},"\u002Fchangelog\u002F2026\u002F04\u002Fsnapshot-diff-viewer\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1479,"title":1480,"subfeature":1222,"showOnPricing":1257,"tiers":1481},"version-history-timeline","Version History Timeline",{"edge":1222,"hub":1222,"fleet":1222},{"id":1483,"title":1484,"tiers":1485},"unlimited-workflow-executions","Unlimited Workflow Executions",{"edge":1222,"hub":1222,"fleet":1222},{"id":1487,"title":1488,"description":1489,"tiers":1490},"device-fleet-updates","Device Fleet Updates","Connect to edge devices to quickly assess and update logic. Debug one device and roll out improvements to your fleet in minutes, securely without requiring full device access for your whole organisation.",{"edge":1222,"hub":1257,"fleet":1222},{"id":1492,"title":1493,"description":1494,"docsLink":1495,"tiers":1496},"device-group-management","Device Group Management","Logically group devices assigned to an application and integrate device groups into your DevOps Pipeline for coordinated fleet updates.","\u002Fdocs\u002Fuser\u002Fdevice-groups\u002F",{"edge":1222,"hub":1257,"fleet":1222},{"id":1498,"title":1499,"description":1500,"docsLink":1501,"tiers":1502},"high-availability","High Availability","Leverage horizontal scaling for reliable and scalable processing of your data through Node-RED.","\u002Fdocs\u002Fuser\u002Fhigh-availability\u002F",{"edge":1257,"hub":1222,"fleet":1257},{"id":1504,"title":1505,"description":1506,"tiers":1507},"performance-monitoring","Performance Monitoring & Alerts","Track CPU, memory, and event loop performance across your instances and devices, with email alerts when something needs your attention.",{"edge":1222,"hub":1222,"fleet":1222},{"id":1509,"title":1510,"description":1511,"docsLink":1512,"subfeature":1222,"showOnPricing":1257,"tiers":1513},"instance-monitoring","Instance Monitoring","Enable alerts to be sent via email when your Node-RED instances encounter issues.","\u002Fdocs\u002Fuser\u002Finstance-settings\u002F#alerts",{"edge":1222,"hub":1222,"fleet":1222},{"id":1515,"title":1516,"subfeature":1222,"showOnPricing":1257,"tiers":1517},"email-alerts","Email Alerts",{"edge":1222,"hub":1222,"fleet":1222},{"id":1519,"title":1520,"showOnPricing":1257,"tiers":1521},"api-debug-length-limit","API\u002FDebug Length Limit",{"edge":1222,"hub":1222,"fleet":1222},{"id":1523,"title":1524,"tiers":1525},"protected-instances","Protected Instances",{"edge":1257,"hub":1222,"fleet":1257},{"id":1527,"title":1528,"features":1529},"govern-secure","Govern and Secure",[1530,1539,1545,1551,1556,1562,1568,1574,1582,1588,1594,1600],{"id":1531,"title":1532,"description":1533,"docsLink":1534,"changelog":1535,"tiers":1538},"single-sign-on","Single Sign-On (SSO)","Configure FlowFuse to work with your own SSO provider, allowing users to access FlowFuse with a single set of login credentials.","\u002Fdocs\u002Fadmin\u002Fsso\u002F",[1536],{"url":1537,"release":1310},"\u002Fchangelog\u002F2026\u002F07\u002Fapplication-sso-groups\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1540,"title":1541,"description":1542,"docsLink":1543,"tiers":1544},"two-factor-authentication","Two-Factor Authentication","Two-factor authentication adds an extra layer of security to your FlowFuse account.","\u002Fdocs\u002Fuser\u002Fuser-settings\u002F#two-factor-authentication",{"edge":1222,"hub":1222,"fleet":1222},{"id":1546,"title":1547,"description":1548,"docsLink":1549,"tiers":1550},"certified-nodes-it","Certified Nodes - IT","IT certified node bundle includes: Redis, MQTT, HTTP Request, AI nodes (Gemini, Claude, ChatGPT, Ollama), MCP Server","\u002Fblog\u002F2025\u002F07\u002Fcertified-nodes-v2\u002F",{"edge":1257,"hub":1222,"fleet":1222},{"id":1552,"title":1553,"description":1554,"tiers":1555},"certified-nodes-ot","Certified OT Connections - OPC-UA, Modbus, etc.","OT certified node bundle includes: OPC-UA, Modbus TCP & RTU, RTSP, EtherNet\u002FIP, AI nodes (Gemini, Claude, ChatGPT, Ollama), MCP Server",{"edge":1222,"hub":1257,"fleet":1257},{"id":1557,"title":1558,"description":1559,"docsLink":1560,"tiers":1561},"audit-log","Audit Log","Keep track of everything going on in your Node-RED instances and FlowFuse. Audit Logs provide details on what actions have taken place, when they happened, and who did them.","\u002Fdocs\u002Fuser\u002Flogs\u002F#audit-log",{"edge":1222,"hub":1222,"fleet":1222},{"id":1563,"title":1564,"description":1565,"docsLink":1566,"tiers":1567},"role-based-access-control","Role-Based Access Control","Control who can do what at both the team and application level, from viewers to admins.","\u002Fdocs\u002Fuser\u002Frole-based-access-control\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1569,"title":1570,"description":1571,"docsLink":1572,"subfeature":1222,"showOnPricing":1257,"tiers":1573},"application-level-rbac","Application-Level RBAC","Fine-grained access control per application, allowing team members to have different permission levels across different applications without requiring separate teams.","\u002Fdocs\u002Fuser\u002Frole-based-access-control\u002F#application-level-rbac",{"edge":1222,"hub":1222,"fleet":1222},{"id":1575,"title":1576,"description":1577,"changelog":1578,"subfeature":1222,"showOnPricing":1257,"tiers":1581},"scoped-personal-access-tokens","Scoped Personal Access Tokens","Restrict a Personal Access Token to specific teams, limit it to read-only operations, or control whether it carries admin privileges.",[1579],{"url":1580,"release":1310},"\u002Fchangelog\u002F2026\u002F07\u002Fscoped-pats\u002F",{"edge":1222,"hub":1222,"fleet":1222},{"id":1583,"title":1584,"description":1585,"docsLink":1586,"showOnPricing":1257,"tiers":1587},"team-members","Team Members","Invite multiple team members to collaborate on the same Node-RED flows.","\u002Fdocs\u002Fuser\u002Fteam\u002F#teams",{"edge":1222,"hub":1222,"fleet":1222},{"id":1589,"title":1590,"description":1591,"docsLink":1592,"showOnPricing":1257,"tiers":1593},"endpoint-security","Endpoint Security","Secure HTTP endpoints for hosted Node-RED instances using FlowFuse credentials.","\u002Fdocs\u002Fuser\u002Finstance-settings\u002F#security",{"edge":1222,"hub":1222,"fleet":1222},{"id":1595,"title":1596,"description":1597,"docsLink":1598,"tiers":1599},"baa-for-hipaa","BAA for HIPAA","FlowFuse can sign a Business Associate Agreement to ensure proper safeguarding of protected health information handled on your behalf.","\u002Fhandbook\u002Fsales\u002Fsubscription-agreement-1.5\u002F",{"edge":1257,"hub":1222,"fleet":1257},{"id":1601,"title":1602,"description":1603,"tiers":1604},"sbom","Software Bill of Materials","A complete list of all software components used in your Node-RED instances and hosted applications, including version numbers and license information.",{"edge":1257,"hub":1222,"fleet":1257},{"id":1606,"title":1607,"features":1608},"support","Support",[1609,1614,1618],{"id":1610,"title":1611,"docsLink":1612,"tiers":1613},"installation-support","Installation Support","\u002Fdocs\u002Finstall\u002Fintroduction\u002F#do-you-need-help-installation-service",{"edge":1222,"hub":1222,"fleet":1222},{"id":1615,"title":1616,"showOnPricing":1257,"tiers":1617},"live-chat-support","Live Chat Support",{"edge":1222,"hub":1222,"fleet":1222},{"id":1619,"title":1620,"docsLink":1621,"tiers":1622},"enterprise-support","Enterprise Support","\u002Fdocs\u002Fpremium-support\u002F",{"edge":1222,"hub":1222,"fleet":1222},"feature-catalog","0AnkhTIPCECCwP9NmbTWP5HvRYx4FTSao4lG93-HaWM",[1626,1634,1653,1664],{"name":1627,"order":1628,"children":1629},"FlowFuse User Manuals",1,[1630],{"title":1631,"path":1632,"group":1627,"groupOrder":1628,"order":1188,"children":1633},"FlowFuse API","\u002Fdocs\u002Fapi",[],{"name":1635,"order":1185,"children":1636},"FlowFuse Self-Hosted",[1637,1641],{"title":1638,"path":1639,"group":1635,"groupOrder":1185,"order":1628,"children":1640},"Quick Start","\u002Fdocs\u002Fquick-start",[],{"title":1642,"path":1643,"group":1635,"groupOrder":1185,"order":1191,"children":1644},"Upgrading FlowFuse","\u002Fdocs\u002Fupgrade",[1645,1649],{"title":1646,"path":1647,"order":1219,"children":1648},"Installing a license","\u002Fdocs\u002Fupgrade\u002Fopen-source-to-premium",[],{"title":1650,"path":1651,"order":1219,"children":1652},"Upgrading the Node-RED version","\u002Fdocs\u002Fupgrade\u002Fnodered-version",[],{"name":1607,"order":1654,"children":1655},5,[1656,1660],{"title":1657,"path":1658,"group":1607,"groupOrder":1654,"order":1191,"children":1659},"Premium Support","\u002Fdocs\u002Fpremium-support",[],{"title":1661,"path":1662,"group":1607,"groupOrder":1654,"order":1219,"children":1663},"Debugging Node-RED issues","\u002Fdocs\u002Fdebugging",[],{"name":1665,"order":1219,"children":1666},"Other",[1667,1713,1725,1804,1853,1872,1946,1957],{"title":1668,"path":1669,"order":1219,"children":1670},"admin","\u002Fdocs\u002Fadmin",[1671,1675,1685,1693,1697,1701,1705,1709],{"title":1672,"path":1673,"order":1628,"children":1674},"Administering FlowFuse","\u002Fdocs\u002Fadmin\u002Fintroduction",[],{"title":1676,"path":1677,"order":1219,"children":1678},"Configuring Single Sign-On (SSO)","\u002Fdocs\u002Fadmin\u002Fsso",[1679,1683],{"title":1680,"path":1681,"order":1219,"children":1682},"LDAP SSO","\u002Fdocs\u002Fadmin\u002Fsso\u002Fldap",[],{"title":1221,"path":1224,"order":1219,"children":1684},[],{"title":1686,"path":1687,"order":1219,"children":1688},"hardening","\u002Fdocs\u002Fadmin\u002Fhardening",[1689],{"title":1690,"path":1691,"order":1219,"children":1692},"Kubernetes Hardening","\u002Fdocs\u002Fadmin\u002Fhardening\u002Fkubernetes",[],{"title":1694,"path":1695,"order":1219,"children":1696},"Monitoring","\u002Fdocs\u002Fadmin\u002Fmonitoring",[],{"title":1698,"path":1699,"order":1219,"children":1700},"Observability","\u002Fdocs\u002Fadmin\u002Fobservability",[],{"title":1702,"path":1703,"order":1219,"children":1704},"Soft Launch Enablement","\u002Fdocs\u002Fadmin\u002Ffeature-flags",[],{"title":1706,"path":1707,"order":1219,"children":1708},"Telemetry","\u002Fdocs\u002Fadmin\u002Ftelemetry",[],{"title":1710,"path":1711,"order":1219,"children":1712},"User Management","\u002Fdocs\u002Fadmin\u002Fuser-management",[],{"title":1714,"path":1715,"order":1219,"children":1716},"cloud","\u002Fdocs\u002Fcloud",[1717,1721],{"title":1718,"path":1719,"order":1628,"children":1720},"Introduction","\u002Fdocs\u002Fcloud\u002Fintroduction",[],{"title":1722,"path":1723,"order":1219,"children":1724},"FlowFuse Cloud Billing","\u002Fdocs\u002Fcloud\u002Fbilling",[],{"title":1726,"path":1727,"order":1219,"children":1728},"contribute","\u002Fdocs\u002Fcontribute",[1729,1732,1736,1740,1744,1748,1752,1760,1796,1800],{"title":1718,"path":1730,"order":1628,"children":1731},"\u002Fdocs\u002Fcontribute\u002Fintroduction",[],{"title":1733,"path":1734,"order":1219,"children":1735},"Adding Template Settings","\u002Fdocs\u002Fcontribute\u002Fadding-template-settings",[],{"title":1737,"path":1738,"order":1219,"children":1739},"API Design","\u002Fdocs\u002Fcontribute\u002Fapi-design",[],{"title":1741,"path":1742,"order":1219,"children":1743},"Creating debug stack containers","\u002Fdocs\u002Fcontribute\u002Fcreating-debug-stack-containers",[],{"title":1745,"path":1746,"order":1219,"children":1747},"Database migrations","\u002Fdocs\u002Fcontribute\u002Fdb-migrations",[],{"title":1749,"path":1750,"order":1219,"children":1751},"FlowFuse Architecture","\u002Fdocs\u002Fcontribute\u002Farchitecture",[],{"title":1753,"path":1754,"order":1219,"children":1755},"Local Install","\u002Fdocs\u002Fcontribute\u002Flocal",[1756],{"title":1757,"path":1758,"order":1219,"children":1759},"Local Stacks","\u002Fdocs\u002Fcontribute\u002Flocal\u002Fstacks",[],{"title":1761,"path":1762,"order":1219,"children":1763},"State Flows","\u002Fdocs\u002Fcontribute\u002Fworkflows",[1764,1768,1772,1776,1780,1784,1788,1792],{"title":1765,"path":1766,"order":1219,"children":1767},"Device Editor","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Fdevice-editor",[],{"title":1769,"path":1770,"order":1219,"children":1771},"Instance states","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Fproject-states",[],{"title":1773,"path":1774,"order":1219,"children":1775},"Invite External Users","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Finvite-external-user",[],{"title":1777,"path":1778,"order":1219,"children":1779},"Project Creation","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Fproject-create",[],{"title":1781,"path":1782,"order":1219,"children":1783},"Reset Password Flow","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Fpassword-reset",[],{"title":1785,"path":1786,"order":1219,"children":1787},"Team creation Flow","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Fteam-create",[],{"title":1789,"path":1790,"order":1219,"children":1791},"User Login Flows","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Flogin",[],{"title":1793,"path":1794,"order":1219,"children":1795},"User Sign up Flow","\u002Fdocs\u002Fcontribute\u002Fworkflows\u002Fsignup",[],{"title":1797,"path":1798,"order":1219,"children":1799},"Team Broker","\u002Fdocs\u002Fcontribute\u002Fteam-broker",[],{"title":1801,"path":1802,"order":1219,"children":1803},"Working with Feature Flags","\u002Fdocs\u002Fcontribute\u002Ffeature-flags",[],{"title":1805,"path":1806,"order":1219,"children":1807},"device-agent","\u002Fdocs\u002Fdevice-agent",[1808,1812,1815,1819,1823,1828],{"title":1809,"path":1810,"order":1628,"children":1811},"FlowFuse Device Agent Introduction","\u002Fdocs\u002Fdevice-agent\u002Fintroduction",[],{"title":1638,"path":1813,"order":1188,"children":1814},"\u002Fdocs\u002Fdevice-agent\u002Fquickstart",[],{"title":1816,"path":1817,"order":1185,"children":1818},"Register your Remote Instance","\u002Fdocs\u002Fdevice-agent\u002Fregister",[],{"title":1820,"path":1821,"order":1654,"children":1822},"Running the Agent","\u002Fdocs\u002Fdevice-agent\u002Frunning",[],{"title":1824,"path":1825,"order":1826,"children":1827},"Deploying your Flows","\u002Fdocs\u002Fdevice-agent\u002Fdeploy",6,[],{"title":1829,"path":1830,"order":1219,"children":1831},"install","\u002Fdocs\u002Fdevice-agent\u002Finstall",[1832,1837,1841,1845,1849],{"title":1833,"path":1834,"group":1835,"order":1628,"children":1836},"Overview","\u002Fdocs\u002Fdevice-agent\u002Finstall\u002Foverview","DeviceAgentInstallation",[],{"title":1838,"path":1839,"group":1835,"order":1188,"children":1840},"Device Agent Installer","\u002Fdocs\u002Fdevice-agent\u002Finstall\u002Fdevice-agent-installer",[],{"title":1842,"path":1843,"group":1835,"order":1191,"children":1844},"Docker Install","\u002Fdocs\u002Fdevice-agent\u002Finstall\u002Fdocker",[],{"title":1846,"path":1847,"group":1835,"order":1185,"children":1848},"Kubernetes Install","\u002Fdocs\u002Fdevice-agent\u002Finstall\u002Fkubernetes",[],{"title":1850,"path":1851,"group":1835,"order":1654,"children":1852},"Manual Install with NPM","\u002Fdocs\u002Fdevice-agent\u002Finstall\u002Fmanual",[],{"title":1854,"path":1855,"order":1219,"children":1856},"hardware","\u002Fdocs\u002Fhardware",[1857,1860,1864,1868],{"title":1833,"path":1858,"order":1628,"children":1859},"\u002Fdocs\u002Fhardware\u002Fintroduction",[],{"title":1861,"path":1862,"order":1188,"children":1863},"ctrlX - Node-RED","\u002Fdocs\u002Fhardware\u002Fctrlx-node-red",[],{"title":1865,"path":1866,"order":1191,"children":1867},"ctrlX - Device Agent","\u002Fdocs\u002Fhardware\u002Fctrlx-device-agent",[],{"title":1869,"path":1870,"order":1191,"children":1871},"Raspberry Pi with Raspbian","\u002Fdocs\u002Fhardware\u002Fraspbian",[],{"title":1829,"path":1873,"order":1219,"children":1874},"\u002Fdocs\u002Finstall",[1875,1878,1882,1886,1906,1910,1914,1918],{"title":1833,"path":1876,"order":1628,"children":1877},"\u002Fdocs\u002Finstall\u002Fintroduction",[],{"title":1879,"path":1880,"order":1219,"children":1881},"Configuring FlowFuse","\u002Fdocs\u002Finstall\u002Fconfiguration",[],{"title":1883,"path":1884,"order":1219,"children":1885},"DNS Setup","\u002Fdocs\u002Finstall\u002Fdns-setup",[],{"title":1887,"path":1888,"order":1219,"children":1889},"Docker install","\u002Fdocs\u002Finstall\u002Fdocker",[1890,1894,1898,1902],{"title":1891,"path":1892,"order":1219,"children":1893},"Add Project Stacks on Docker","\u002Fdocs\u002Finstall\u002Fdocker\u002Fstacks",[],{"title":1895,"path":1896,"order":1219,"children":1897},"Docker Engine on Windows","\u002Fdocs\u002Finstall\u002Fdocker\u002Fwindows-docker-ce",[],{"title":1899,"path":1900,"order":1219,"children":1901},"Docker from AWS Market Place","\u002Fdocs\u002Finstall\u002Fdocker\u002Faws-marketplace",[],{"title":1903,"path":1904,"order":1219,"children":1905},"Docker on Digital Ocean","\u002Fdocs\u002Finstall\u002Fdocker\u002Fdigital-ocean",[],{"title":1907,"path":1908,"order":1219,"children":1909},"Email configuration","\u002Fdocs\u002Finstall\u002Femail-providers",[],{"title":1911,"path":1912,"order":1219,"children":1913},"First Run Setup","\u002Fdocs\u002Finstall\u002Ffirst-run",[],{"title":1915,"path":1916,"order":1219,"children":1917},"FlowFuse File Storage","\u002Fdocs\u002Finstall\u002Ffile-storage",[],{"title":1919,"path":1920,"order":1219,"children":1921},"Install FlowFuse on Kubernetes","\u002Fdocs\u002Finstall\u002Fkubernetes",[1922,1926,1930,1934,1938,1942],{"title":1923,"path":1924,"order":1219,"children":1925},"AWS EKS Installation","\u002Fdocs\u002Finstall\u002Fkubernetes\u002Faws",[],{"title":1927,"path":1928,"order":1219,"children":1929},"AWS EKS Installation with Terraform and Helm","\u002Fdocs\u002Finstall\u002Fkubernetes\u002Faws-terraform",[],{"title":1931,"path":1932,"order":1219,"children":1933},"Digital Ocean Kubernetes Installation","\u002Fdocs\u002Finstall\u002Fkubernetes\u002Fdigital-ocean",[],{"title":1935,"path":1936,"order":1219,"children":1937},"Ingress Controller Migration","\u002Fdocs\u002Finstall\u002Fkubernetes\u002Fingress-controller-migration",[],{"title":1939,"path":1940,"order":1219,"children":1941},"Kubernetes Project Stacks","\u002Fdocs\u002Finstall\u002Fkubernetes\u002Fstacks",[],{"title":1943,"path":1944,"order":1219,"children":1945},"OpenShift Installation","\u002Fdocs\u002Finstall\u002Fkubernetes\u002Fopenshift",[],{"title":1947,"path":1948,"order":1219,"children":1949},"migration","\u002Fdocs\u002Fmigration",[1950,1953],{"title":1718,"path":1951,"order":1628,"children":1952},"\u002Fdocs\u002Fmigration\u002Fintroduction",[],{"title":1954,"path":1955,"order":1219,"children":1956},"Node-RED Tools plugin","\u002Fdocs\u002Fmigration\u002Fnode-red-tools",[],{"title":1958,"path":1959,"order":1219,"children":1960},"user","\u002Fdocs\u002Fuser",[1961,1965,1969,1973,1977,1982,1986,1989,1993,1997,2000,2004,2016,2020,2024,2028,2032,2035,2039,2043,2047,2051,2055,2058,2062,2066,2069,2073],{"title":1962,"path":1963,"order":1628,"children":1964},"Getting Started","\u002Fdocs\u002Fuser\u002Fintroduction",[],{"title":1966,"path":1967,"order":1628,"children":1968},"Static asset service","\u002Fdocs\u002Fuser\u002Fstatic-asset-service",[],{"title":1970,"path":1971,"order":1188,"children":1972},"Bill of Materials","\u002Fdocs\u002Fuser\u002Fbill-of-materials",[],{"title":1974,"path":1975,"order":1188,"children":1976},"FlowFuse Concepts","\u002Fdocs\u002Fuser\u002Fconcepts",[],{"title":1978,"path":1979,"order":1980,"children":1981},"Instance States","\u002Fdocs\u002Fuser\u002Finstance-states",10,[],{"title":1983,"path":1984,"order":1219,"children":1985},"Changing the Stack","\u002Fdocs\u002Fuser\u002Fchangestack",[],{"title":1408,"path":1987,"order":1219,"children":1988},"\u002Fdocs\u002Fuser\u002Fcustom-hostnames",[],{"title":1990,"path":1991,"order":1219,"children":1992},"Custom Node Packages","\u002Fdocs\u002Fuser\u002Fcustom-npm-packages",[],{"title":1994,"path":1995,"order":1219,"children":1996},"Dashboards","\u002Fdocs\u002Fuser\u002Fdashboards",[],{"title":1426,"path":1998,"order":1219,"children":1999},"\u002Fdocs\u002Fuser\u002Fdevops-pipelines",[],{"title":2001,"path":2002,"order":1219,"children":2003},"Environment Variables","\u002Fdocs\u002Fuser\u002Fenvvar",[],{"title":2005,"path":2006,"order":1219,"children":2007},"FlowFuse Expert","\u002Fdocs\u002Fuser\u002Fexpert",[2008,2012],{"title":2009,"path":2010,"order":1219,"children":2011},"AI in Node-RED","\u002Fdocs\u002Fuser\u002Fexpert\u002Fnode-red-embedded-ai",[],{"title":2013,"path":2014,"order":1219,"children":2015},"Chat Interface","\u002Fdocs\u002Fuser\u002Fexpert\u002Fchat",[],{"title":2017,"path":2018,"order":1219,"children":2019},"FlowFuse File Nodes","\u002Fdocs\u002Fuser\u002Ffilenodes",[],{"title":2021,"path":2022,"order":1219,"children":2023},"FlowFuse MQTT Nodes","\u002Fdocs\u002Fuser\u002Fmqtt-nodes",[],{"title":2025,"path":2026,"order":1219,"children":2027},"FlowFuse Persistent Context","\u002Fdocs\u002Fuser\u002Fpersistent-context",[],{"title":2029,"path":2030,"order":1219,"children":2031},"FlowFuse Project Nodes","\u002Fdocs\u002Fuser\u002Fprojectnodes",[],{"title":1304,"path":2033,"order":1219,"children":2034},"\u002Fdocs\u002Fuser\u002Fff-tables",[],{"title":2036,"path":2037,"order":1219,"children":2038},"Groups","\u002Fdocs\u002Fuser\u002Fdevice-groups",[],{"title":2040,"path":2041,"order":1219,"children":2042},"High Availability mode","\u002Fdocs\u002Fuser\u002Fhigh-availability",[],{"title":2044,"path":2045,"order":1219,"children":2046},"HTTP Access Tokens","\u002Fdocs\u002Fuser\u002Fhttp-access-tokens",[],{"title":2048,"path":2049,"order":1219,"children":2050},"Instance Settings","\u002Fdocs\u002Fuser\u002Finstance-settings",[],{"title":2052,"path":2053,"order":1219,"children":2054},"Logging","\u002Fdocs\u002Fuser\u002Flogs",[],{"title":1564,"path":2056,"order":1219,"children":2057},"\u002Fdocs\u002Fuser\u002Frole-based-access-control",[],{"title":2059,"path":2060,"order":1219,"children":2061},"Shared Team Library","\u002Fdocs\u002Fuser\u002Fshared-library",[],{"title":2063,"path":2064,"order":1219,"children":2065},"Snapshots","\u002Fdocs\u002Fuser\u002Fsnapshots",[],{"title":1797,"path":2067,"order":1219,"children":2068},"\u002Fdocs\u002Fuser\u002Fteambroker",[],{"title":2070,"path":2071,"order":1219,"children":2072},"Teams","\u002Fdocs\u002Fuser\u002Fteam",[],{"title":2074,"path":2075,"order":1219,"children":2076},"User Settings","\u002Fdocs\u002Fuser\u002Fuser-settings",[],1786717925110]