Live data from Hacker News

Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

github.com

81–90 of 101 posts

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#81
post #34

Earlier quoted context omitted.

I've written one of these 204-page PDFs before (I think it was more like 20 pages though). The IDPs don't exactly make it easy on their customers to set this stuff up, and the burden ends up on the SP (i.e. you) to document to folks how to use their own IDP. Incidentally we just shipped something for this. Rather than having to make a 204-page PDF, you can go into SSOReady, generate a setup URL, and give it to custom…

Wow. My company previously did an SSO implementation for our SaaS where we ran Shibboleth SP behind Apache just for SSO, with a little Python web app using mod_wsgi to call back to the main web app after SSO was completed. But for the customers that we've onboarded to SSO so far, we had to contract with a SAML expert to work with the customer to set it up. This self-service setup might be enough to make it worth our…

Sounds horrible, why would you use Shibboleth in $currentyear if you could just use OIDC?

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#82
post #47

Congrats on the launch! How does this compare to BoxyHQ's SAML Jackson [1]? [1]: https://github.com/boxyhq/jackson

We think BoxyHQ does a nice job. We prefer our approach for basically two reasons: 1. BoxyHQ wants you to do SAML-over-OAuth. We support this -- especially for NextAuth compatibility. But we don't think it's always helpful. 2. We think our service is easier to use. We most commonly hear complaints from users/customers about complexity, so we try really hard to make SAML obvious and simple. Ultimately, it's up to you…

Would you mind elaborating a bit why you don’t think SAML-over-OAuth is a fits-all solution? To me it sounds like eating your cake (SAML) and having it too (not having to use SAML)

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#83
post #76
post #72

For info, the documentation for the project https://ssoready.com/docs seems down: 502 ERROR The request could not be satisfied. CloudFront wasn't able to connect to the origin. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner. If you provide content to customers through CloudFront, you ca…

Thank you for letting us know! Are you still unable to use https://ssoready.com/docs ?

All good now

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#85
Thank you for this, it’s sorely needed.

One thing I didn’t see mention of is group membership. Is this / will this be part of the core offering? Being able to map IDP group membership to permissions within your SaaS is powerful, and in my experience highly desired by clients.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#86

Earlier quoted context omitted.

> Add to that the very often the people you're integrating with have no concept of SAML, its workflows, its payloads, etc., much less the capabilities of their own stack in regards to SAML. So you get to train them (and learn about their system) at the same time. This is true of a great many protocols, unfortunately. I've seen this with IPSec, HL7v2, … CSV . IPSec was perhaps the most … scarring. Always sort of feeli…

HL7v2, the protocol of "we just put all the data in this one random field".

Delimited with ^, |, ~ and &, which is sure to never create issues.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#87
This may be offtopic but I am looking for SSO integration advise for integrating with multiple IdPs.

I am building a SaaS application and wants to allow customers from different companies , each with their on IdP to be able to SSO into my application , which is a multi-tenant SaaS offering.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#88

Earlier quoted context omitted.

Ya with the last decade of experience I'm never building on top of a vc backed open source project. These things are mutually exclusive IMO. I'm not saying you can't build a solid business around open source. I mean red hat did it, but that is the model you have to go for. Not VC money at seed stage.

Out of curiosity, who else did it besides RedHat ( who are building Linux distros AFAIK ) ? How do you expect people to bootstrap an infra SaaS? I just don’t see how you can seriously attempt something like an Auth0 competitor startup without any money. I mean it’s nice to not take VC money but you are going to be broke for a long long time - and you still have the same failure rate as with VC. So you need to be supe…

> How do you expect people to bootstrap an infra SaaS?

Presumably ilrwbwrkhv is thinking of the fate of ElasticSearch, MongoDB, Redis, CockroachDB, Confluent, TimescaleDB, Terraform, HashiCorp Vault, Docker Desktop and suchlike.

The VCs want a return for all the money they've invested, and it's difficult to monetise a free product.

One way to avoid letting down your community is to have your product be a closed-source paid product from day 1. Another is to get the backing of a huge multinational with endless ad revenue. Another is to run a super lean one-man operation, or get a day job and make free software your hobby. Another is to teeter on the edge of bankruptcy and hope one of your users just acquires your entire company.

Or you can just disappoint your community - SAML's only used by faceless megacorporations anyway, it's not like you'd be letting down real people.

None of these are great options IMHO - but that's why I don't have a VC-funded infrastructure startup myself :)

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#89

Earlier quoted context omitted.

Ya with the last decade of experience I'm never building on top of a vc backed open source project. These things are mutually exclusive IMO. I'm not saying you can't build a solid business around open source. I mean red hat did it, but that is the model you have to go for. Not VC money at seed stage.

Out of curiosity, who else did it besides RedHat ( who are building Linux distros AFAIK ) ? How do you expect people to bootstrap an infra SaaS? I just don’t see how you can seriously attempt something like an Auth0 competitor startup without any money. I mean it’s nice to not take VC money but you are going to be broke for a long long time - and you still have the same failure rate as with VC. So you need to be supe…

Laravel and that whole ecosystem is another great example. Open source is slow and a grass roots movement. That's what I mean, when people think it is venture scale, they are either being dishonest to the investors or to the users. Because one day the ethos of open source has to be broken to make the real money. Better to make it a paid product from day 1 instead of playing this game.

One of my favorite bad examples of this is Supabase. They played into the whole open source Firebase bandwagon and while their code is available, the ethos of open source is completely lost, so much so that even now local development and self hosting is a pain.

In terms of good examples, Andrew Sherman who does Drizzle ORM is a good example of this. Here is one of his tweets talking about not taking VC money: https://x.com/andrii_sherman/status/1775954643022971044

> I quit my job to start working on Drizzle full-time. It's still not VC-backed(and will never be!), and we are still doing everything thanks to our great sponsors and our first successful B2B integrations.

So it can work but honestly the best open source projects start off when you are getting paid a salary and you work on the project because you are passionate and love working on it.

Re: Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source

#90
post #84

It sounds great. Any chance to get this ported to other major programming languages (Java, C++, Go, Rust, C#)?

The interface between your app and SSOReady is entirely over an HTTP API. We codegen SDKs for that HTTP API for Python and TypeScript, and will add more, but in the meantime the docs show you the curl you'd need to port:

https://ssoready.com/docs/api-reference/saml/redeem-saml-acc...

Post reply on HN