This topic describes how to integrate Alibaba Cloud IDaaS applications with a SAML 2.0 identity source on the Mobi platform.
Create an IDaaS application
In Alibaba Cloud IDaaS EIAM, create an application that uses the SAML 2.0 protocol and name it
mobi-saml-example.Open the IDaaS IdP metadata URL in a browser to view the SAML IdP information. Then, copy the IDaaS IdP metadata.

Configure the assertion attributes that IDaaS returns.
Create a SAML identity source in the Mobi platform
Enter the basic information for the identity source.
Paste the IDaaS IdP metadata that you copied from the IDaaS application into Mobi to complete the import.
Configure other advanced properties.
NoteThe configurations for properties such as Post Binding Request, Post Binding Response, Post Binding Logout, and Name ID Policy Format must match the assertion attributes returned by IDaaS.
Configure identity attribute mappings.
NoteConfigure the identity attribute mappings based on the SAML assertion attributes that you set in the IDaaS application.
Configure the Username mapping.
Configure the Email mapping.
Configure the Phone Number mapping.
Configure the Nickname mapping.
Configure permission group mappings.
By default, all users who log on from the IDaaS identity source are mapped to the END_USER permission group. Users with a status of `enabled` are mapped to the HR1 permission group. You can change the permission groups as needed.
View and copy the metadata URL of the Mobi SAML 2.0 identity source.
IDaaS application configuration
Paste the metadata URL from the previous step into the metadata configuration section of the IDaaS application.
Add an account in IDaaS.
Verify the logon in Mobi
Create an application and select SAML 2.0 as the default logon method for PCs.
After you publish and access the application, the IDaaS logon interface is displayed.
After a successful logon, the corresponding user information is displayed in the Mobi user management interface.