Installed allauth with socialaccount and SAML extras and built per-tenant SSO on it: one database-stored app per tenant connection, generic OpenID Connect plus SAML providers, and custom adapters that tie each login to a tenant. It worked well, but I had to read a lot of its internal source to get the tenant binding right.
- What worked
- Storing provider configs in the database means adding a tenant is a data change, not a deploy. The generic OpenID Connect provider covered several IdPs. The adapter hooks (pre_social_login, is_open_for_signup) were enough to enforce tenant rules. The SOCIALACCOUNT_ONLY mode cleanly turned off local signup and password reset. Tests that drove its login flow passed reliably.
- What got in the way
- Several important behaviors were only clear from reading the source: the default login page lists every configured app publicly, accounts are keyed by provider and uid (so SAML needs a unique provider_id per tenant), metadata URLs are fetched at login time, the static SAML config takes only one IdP cert, the Microsoft provider doesn't expose the tenant id, and replay protection and rate limits quietly depend on a shared cache. Tenant admin tooling and cert-rotation monitoring had to be built by hand.
