Hugging Face

How to Configure SAML 2.0 for Hugging Face Enterprise Hub

Prerequisites:

  • Your organization must be on an Enterprise or Enterprise Plus plan to enable SAML-based SSO.
  • You must have administrator access to both your Okta organization and your Hugging Face Enterprise Hub organization.
  • For details about Hugging Face’s SSO options, visit the official documentation: Hugging Face Enterprise SSO Documentation.

Contents


Supported Features

The Okta / Hugging Face Enterprise Hub SAML integration supports the following:


Configuration Steps

Step 1 — Add the Hugging Face App from Okta Integration Network (OIN)

  1. Sign in to your Okta Admin Dashboard.
  2. Go to Applications → Browse App Catalog.
  3. Search for and select the application named Hugging Face.
  4. Click Add Integration.

Step 2 — Configure the Hugging Face App in Okta

  1. On the General Settings page, enter:
    • Application label: Hugging Face
    • Organization Name: Your Hugging Face organization name
    • Organization ID: Your Hugging Face organization ID

    Where to find these values: In Hugging Face, go to Organization Settings → SSO → SAML. You will see both the Organization Name and Organization ID.

    Hugging Face SSO SAML screenshot

  2. Click Next, review the Sign-On Options (username format should be Email), then click Done.
  3. Important: Ensure the administrator performing these steps is assigned to the Hugging Face app in Okta (via the Assignments tab).

Step 3 — Copy SAML Configuration from Okta

  1. In the Hugging Face app in Okta, open the Sign On tab.
  2. Locate the SAML 2.0 section and click View SAML Setup Instructions (or go to Metadata Details).
  3. Copy the following values:
    • Identity Provider Single Sign-On URL
    • X.509 Certificate — copy the full certificate including -----BEGIN CERTIFICATE----- and -----END CERTIFICATE-----.

Step 4 — Configure SAML in Hugging Face

  1. Return to your organization’s Organization Settings → SSO → SAML tab in Hugging Face.
  2. Enter the values from Okta:
    • Sign On URL: Paste the Identity Provider Single Sign-On URL from Okta.
    • X.509 Certificate: Paste the full certificate (including BEGIN/END markers) from Okta.
  3. Click Update and Test SAML Configuration to validate.
  4. If the test is successful, toggle Enable SAML SSO to activate SSO for your organization.

What happens next ? Users will still sign in to Hugging Face with their usual accounts. When they access content belonging to your organization, they’ll be prompted to authenticate via SSO through Okta.


Notes