# Single Logout not working with GitLab and Keycloak

**URL:** <https://forum.keycloak.org/t/single-logout-not-working-with-gitlab-and-keycloak/8215>\
**Category:** Getting advice\
**Tags:** saml\
**Created:** [March 30, 2021, 2:07pm UTC](https://forum.keycloak.org/t/single-logout-not-working-with-gitlab-and-keycloak/8215 "2021-03-30T14:07:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![joel](https://avatars.discourse-cdn.com/v4/letter/j/b9bd4f/32.png) [@joel](https://forum.keycloak.org/u/joel)\
**Post date:** [March 30, 2021, 2:07pm UTC](https://forum.keycloak.org/t/single-logout-not-working-with-gitlab-and-keycloak/8215/1 "2021-03-30T14:07:15Z")

</div>

I intend to set up a Single Sign On/Out experience for the users of our GitLab instance.   
To achieve this, I use Keycloak. I would like all login/logout to be made over our Keycloak instance.

Our GitLab instance is currently configured to use LDAPS for user authentication and SAML looks like the best SSO replacement for that in the case of GitLab.  
Unfortunately I have not yet been able to find a solution to implement Single Logout with GitLab (Login works well). When a user clicks on the sign out button he gets immediately logged back in again. The Keycloak session does not get invalidated and we have the option ‘omniauth\_auto\_sign\_in\_with\_provider’ enabled.

I have tried solving this issue by adding the following to our gitlab.rb file:

```auto
gitlab_rails['omniauth_providers'] = [
 {
    name: 'saml',
    args: {
        ...
        idp_slo_target_url: 'https://keycloak.instance/auth/realms/REALM-NAME/protocol/saml/logout'
        ...
    }
 }
]

```

After adding this and reconfiguring GitLab, there was no noticeable effect however.   
I tried the following pattern for idp\_slo\_target\_url as well:   
[https://keycloak.instance/auth/realms/REALM-NAME/protocol/openid-connect/logout](https://keycloak.instance/auth/realms/REALM-NAME/protocol/openid-connect/logout)

This did not solve the problem.

As a workaround I even tried adding those sign out urls as a “After sign out path” in the GitLab admin GUI under Settings → General → Sign-in restrictions.   
Unfortunately this didn’t work either.

Any help would be very appreciated!

---

<div class="post-metadata">

**Author:** ![nikita-s](https://avatars.discourse-cdn.com/v4/letter/n/2bfe46/32.png) [@nikita-s](https://forum.keycloak.org/u/nikita-s)\
**Post date:** [May 14, 2021, 3:53pm UTC](https://forum.keycloak.org/t/single-logout-not-working-with-gitlab-and-keycloak/8215/2 "2021-05-14T15:53:52Z")

</div>

Hello,

Did you manage to solve the problem?

Thank you.

---

<div class="post-metadata">

**Author:** ![xkey](https://avatars.discourse-cdn.com/v4/letter/x/ce7236/32.png) [@xkey](https://forum.keycloak.org/u/xkey)\
**Post date:** [May 17, 2021, 4:50pm UTC](https://forum.keycloak.org/t/single-logout-not-working-with-gitlab-and-keycloak/8215/3 "2021-05-17T16:50:14Z")

</div>

Hi there,

I’m currently struggling with integrating keycloak into gitlab too to connect via OpenID Connect for authentication and authorization decision.

I use Omnibus GitLab and have also done the configuration steps like @joel

Used this documentations [Link](https://docs.gitlab.com/ce/administration/auth/oidc.html) and [Link](https://gitlab.kricon.co/help/integration/omniauth)

Have you already made progress with the integration?  
Why do you prefer to integrate keycloak with SAML instead of OIDC? Did you also try this protocol? @joel
