August 2026 release is live Read More
Breadcrumbs

Configure RSA Secure ID

Why this matters: Mavvrik only supports SP-initiated SSO (started from Mavvrik's login page) — setup here is about getting the SAML app configured correctly on both ends. RSA's own workflow requires an extra "Publish Changes" step after every edit (noted at the bottom) that's easy to miss and will leave changes not actually live until you do it.

Note: Mavvrik does not support IDP-initiated flow for single sign-on (SSO). In order to use SSO with Mavvrik, you will need to initiate the SSO process from Mavvrik

Here are the steps to create a SAML app in RSA:

  1. Log in to RSA Secure Id admin console

  2. Click on Applications

  3. Click on My Applications

  4. Click "Create from Template"

Create an RSA SecurID application from a template
Create an RSA SecurID application from a template
  1. Click on Select

Select the SAML application template
Select the SAML application template
  1. Enter Name

  2. Click on Next Step

Proceed to the SAML configuration
Proceed to the SAML configuration
  1. Enter Connection URL (Navigate to Mavvrik SSO page under Admin and copy the SP ACS URL)

Copy the Mavvrik ACS URL
Copy the Mavvrik ACS URL
  1. Paste the same connection URL used in above step in Assertion Consumer Service (ACS)

  2. Enter SP Entity ID (Navigate to Mavvrik SSO dashboard under Admin and copy the SP Entity ID)

Copy the Mavvrik entity ID
Copy the Mavvrik entity ID
  1. Copy this Identify Provider URL and paste it in IdP Entity ID and IdP SSO URL in mavvrik sso dashboard.

Enter the RSA identity-provider URLs in Mavvrik
Enter the RSA identity-provider URLs in Mavvrik
  1. Click on Download certificate, open it and copy the certificate and paste it in IdP Certificate in mavvrik sso dashboard.

Upload the RSA identity-provider certificate
Upload the RSA identity-provider certificate
  1. Click on Save in Mavvrik SSO

  2. Go back to RSA secure id dashboard

  3. Click on "Show Connection Profile Advanced Configuration"

  4. Under User Identity select Identifier Type as "emailAddress"

Set the SAML identifier type to emailAddress
Set the SAML identifier type to emailAddress
  1. Click on Next Step

  2. Based on subscription select "Access Policy"

Configure the RSA access policy
Configure the RSA access policy
  1. Click on Next Step

  2. Click on Save and Finish

  3. Click on Access

  4. Click on My Page

Add the application to My Page
Add the application to My Page
  1. Click on My Applications Enable button

  2. Click on Save

Save the RSA application
Save the RSA application
  1. Click on Publish Changes at top right corner.

Publish the RSA application changes
Publish the RSA application changes

NOTE: After every change/edit application publish changes should be done to reflect the changes.