IDP Specific

Why are Keycloak SSO users created in WordPress but given incorrect roles or no roles at all?

4 views 0

Probable Cause:

Grouping or role attributes are not being sent in the SAML response from Keycloak, or role mapping is not configured in the miniOrange plugin.

Solution:

  1. In Keycloak admin → Clients → your client → Mappers, add a mapper for group/role values.
  2. Configure the mapper to include the user’s groups/roles in the SAML response.
  3. In the miniOrange plugin → Attribute/Role Mapping tab, map the incoming group/role attribute to WordPress roles.
  4. Save settings and test login again.

Still need help?

Contact us at samlsupport@xecurify.com

Was this helpful?


Hello there!

Need Help? We are right here!

support