Hugging Face

How to Configure SAML 2.0 for Hugging Face Enterprise Hub

Prerequisites:

  • Your organization must be on an Enterprise or Enterprise Plus plan to enable SAML-based Single Sign-On (SSO).
  • You must have administrator privileges in both your Okta organization and your Hugging Face Enterprise Hub organization.
  • Ensure your Hugging Face organization has a unique Organization Name and Organization ID. You will find these under Organization Settings → SSO → SAML.
  • Have your Okta Identity Provider (IdP) metadata available, including:
    • Identity Provider Single Sign-On URL
    • X.509 Certificate (full text including BEGIN/END markers)
  • For more information about Hugging Face’s Enterprise SSO, see: Hugging Face Enterprise SSO Documentation.

Contents


Supported Features

The Okta / Hugging Face Enterprise Hub SAML integration supports the following features:


Configuration Steps

Step 1 — Add the Hugging Face App from Okta Integration Network (OIN)

  1. Sign in to your Okta Admin Console.
  2. Navigate to Applications → Browse App Catalog.
  3. Search for Hugging Face and click Add Integration.

Step 2 — Configure the Hugging Face App in Okta

  1. On the General Settings page, specify:
    • Application label: Hugging Face
    • Organization Name: Your Hugging Face organization name
    • Organization ID: Your Hugging Face organization ID

    Where to find these values: In Hugging Face, go to Organization Settings → SSO → SAML.

    Hugging Face SSO SAML screenshot

  2. Click Next, review the sign-on options (the username format should be Email), and then click Done.
  3. Important: Ensure the administrator performing these steps is assigned to the Hugging Face app in Okta under the Assignments tab.

Step 3 — Copy SAML Configuration from Okta

  1. In the Hugging Face app in Okta, open the Sign On tab.
  2. Locate the SAML 2.0 section and click View SAML Setup Instructions.
  3. Copy the following values:
    • Identity Provider Single Sign-On URL
    • X.509 Certificate — copy the full text including -----BEGIN CERTIFICATE----- and -----END CERTIFICATE-----.

Step 4 — Configure SAML in Hugging Face

  1. In Hugging Face, navigate to Organization Settings → SSO → SAML.
  2. Enter the values obtained from Okta:
    • Sign On URL: Paste the Identity Provider Single Sign-On URL.
    • X.509 Certificate: Paste the certificate including BEGIN/END markers.
  3. Click Update and Test SAML Configuration.
  4. If the test succeeds, toggle Enable SAML SSO to activate SSO for your organization.

SP-Initiated SSO

Hugging Face also supports SP-initiated Single Sign-On. To initiate login directly from Hugging Face:

  1. Navigate to https://huggingface.co/organizations/{organizationName}/sso
  2. You’ll be redirected to Okta to authenticate, and then returned to your Hugging Face organization workspace.

This flow can also occur automatically when accessing restricted organization content — users will be prompted with a “Login with SSO” banner that redirects to Okta.


Notes


Customer Support Contact

For assistance with SSO setup or troubleshooting, please contact the Hugging Face Enterprise Support team: