Authn.tech
Home
  • SAML 2.0
  • OAuth 2.0
  • OIDC
  • JWT / JOSE
  • WebAuthn / Passkey
  • MFA / TOTP
  • LDAP
  • China Platforms SSO
  • All Tools
  • JWT Decode
  • JWT Sign
  • JWK Gen
  • JWK → PEM
  • PEM → JWK
  • PKCE Gen
  • OIDC Discovery
  • Scan-Login Demo
  • TOTP
  • WebAuthn
  • SAML Codec
  • SAML Metadata
  • SAML Response
  • Feishu SAML
  • X.509 Cert
  • PEM Inspect
  • Base64URL
  • LDAP Filter
  • Overview & Roles
  • OIDC Mock
  • SAML Mock
  • Mail Server
  • LDAP Directory
  • OIDC Login Demo
  • SAML Login Demo
  • WeChat Scan-Login
  • WeCom Scan-Login
  • 简体中文
  • English
  • Deutsch
GitHub
Home
  • SAML 2.0
  • OAuth 2.0
  • OIDC
  • JWT / JOSE
  • WebAuthn / Passkey
  • MFA / TOTP
  • LDAP
  • China Platforms SSO
  • All Tools
  • JWT Decode
  • JWT Sign
  • JWK Gen
  • JWK → PEM
  • PEM → JWK
  • PKCE Gen
  • OIDC Discovery
  • Scan-Login Demo
  • TOTP
  • WebAuthn
  • SAML Codec
  • SAML Metadata
  • SAML Response
  • Feishu SAML
  • X.509 Cert
  • PEM Inspect
  • Base64URL
  • LDAP Filter
  • Overview & Roles
  • OIDC Mock
  • SAML Mock
  • Mail Server
  • LDAP Directory
  • OIDC Login Demo
  • SAML Login Demo
  • WeChat Scan-Login
  • WeCom Scan-Login
  • 简体中文
  • English
  • Deutsch
GitHub
  • Online Tools

    • All Tools
    • JWT / JWK

      • JWT Decode
      • JWT Sign
      • JWK Gen
      • JWK → PEM
      • PEM → JWK
    • OAuth2 / OIDC

      • PKCE Gen
      • Discovery
      • Scan-Login Demo
    • MFA / Passkey

      • TOTP
      • WebAuthn
    • SAML

      • SAML Codec
      • SAML Metadata
      • SAML Response
      • Feishu SAML
    • Certs / Encoding

      • X.509 Cert
      • PEM Inspect
      • Base64URL
    • LDAP

      • LDAP Filter

Feishu SAML SSO Helper

When Feishu acts as an SP integrating with a corporate IdP, it only supports SAML 2.0, and it cannot import IdP metadata—you have to fill in the fields by hand in the admin console. This tool removes the two points of friction in that round trip:

  • Parse IdP Metadata → Feishu fields: paste the metadata exported from Okta / Entra ID / ADFS / IDaaS, and it automatically extracts the Issuer, login URL, logout URL, and NameID format you need to paste into Feishu, plus the Public Certificate with the -----BEGIN/END----- header and footer stripped off (Feishu's field only accepts the bare base64).
  • Generate Feishu SP Metadata: Feishu's SP parameters are fixed per region (China feishu.cn / Global / Singapore / Japan) and are built into the tool. Pick a region and the ACS URL / SP Entity ID fill in automatically, assembling a standard SP metadata document (including the certificate and NameIDFormat) to upload to any IdP that supports importing it.

The certificate rotation trap

The IdP signing certificate in Feishu is hardcoded. After the IdP rotates its signing certificate, you must go back into Feishu and update it manually, or logins will start failing without warning. All computation runs locally in your browser; metadata and certificates are never uploaded.

For the full background on Feishu SP SSO (why it is SAML-only, the field mapping, and the differences from DingTalk), see China-Platform SSO Integration. For general parsing of metadata structure, see SAML Metadata Parser.

Last updated: 7/10/26, 6:40 PM
Contributors: linux, Claude Opus 4.8
Prev
SAML Response