Connect your real Webex test organization.
Two SAML IdPs, separate signing certificates and separate test credentials. Both providers use this lab implementation. Metadata download and sign-in endpoints are real once initialized.
The key is kept in this page's memory only. Do not use a Microsoft or Webex password here.
Unlock to view server configuration.
1. Import the Webex SP metadata
Download the SP XML from your test Control Hub's SSO setup. Choose the IdP below and import it. Repeat for the other IdP. Metadata must contain Webex HTTPS ACS endpoints and a signing certificate.
Importing replaces the selected IdP's SP trust configuration and expires its pending login attempts.
2. Configure the test user
The email must already belong to a user in your Webex test organization. Save a different lab password for each IdP.
3. Test in Control Hub
- Download IdP A's metadata above and import it into the matching Control Hub identity provider.
- For this self-signed metadata, choose the option that accepts self-signed or unsigned metadata.
- Keep the Webex username attribute as uid. The IdP sends the user's email as uid and uses a transient NameID.
- Select Test SSO setup in Control Hub and use a private browser window.
- Sign in with the configured IdP A lab password. Confirm that Webex accepts the result.
- Repeat with IdP B. Record Webex's success result before enabling routing.
Requests must be signed using RSA-SHA256. The service signs both the assertion and response. It does not provision users or implement single logout; every new request prompts for credentials.
Cisco multiple IdPs guideRecent server events
“Response issued” confirms this IdP signed a response. Only a successful result in Webex confirms that Webex accepted it.