Hanko Attribute Mapping Guide:About Hanko:Hanko is a modern open source authentication solution and the fastest way you integrate passkeys, 2FA, SSO, and more—with full control over your data. Move between self-hosted and Hanko Cloud anytime. No lock-in. Just Auth how it should be: secure, user friendly, and fully yours.What This Guide Covers: This guide explains how to map an enterprise or social connection’s own
attributes/claims onto Hanko’s fixed set of standard user profile fields.Prerequisites:
Hanko reads a fixed set of standard profile fields from every enterprise or social connection: - Active Hanko project
- At least one enterprise or social connection configured
- Understand which standard profile fields Hanko reads from a connection
- Map a connection’s attributes/claims onto those fields
- Understand each field’s default when left unmapped
Name,
Given name, Family name, Email, Email verified, and Picture. By default it looks for these under standard
attribute/claim names (a SAML URN, or a same-named claim from the provider) - if your provider sends them under
different names, attribute mapping lets you tell Hanko where to actually find them.
This is distinct from custom claims, which map a connection’s attributes/claims
onto claims you declare yourself, not onto this fixed set.
Enterprise connections
- Log in to Hanko Cloud and select your project.
- Navigate to
Settings > Enterprise connectionsand open (or create) a connection. - Under
Attribute mapping, set each field to the SAML attribute name (or URI) your IdP actually uses. - Click
Save.
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress for Email); Email verified and Picture
have no default at all unless the connection’s name contains “auth0”, in which case Hanko falls back to Auth0’s own
attribute names for them.
Social connections
- Log in to Hanko Cloud and select your project.
- Navigate to
Settings > Social connectionsand open (or create) a custom provider. - Under
Attribute mapping, set each field to the provider’s own claim name to read it from. - Click
Save.
email), if it sends one - most
spec-compliant OIDC providers do by default.
This only applies to custom OAuth/OIDC providers you’ve configured yourself, not the built-in providers (Apple,
Discord, GitHub, Google, LinkedIn, Microsoft).