kickflow SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in kickflow is required.

  • For the latest setup instructions, please check the manual provided by kickflow.

  • Single sign-on functionality is available on kickflow's Enterprise plan.
  • kickflow's SAML JIT only supports creating new accounts. Changes made in TrustLogin are not reflected, so administrators must manually update information in kickflow.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser


iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The app is available as a Progressive Web App (PWA) that can be installed from kickflow's website.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "kickflow (SAML)".
    kickflow01.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    kickflow02.png

    Now, switch to configuring kickflow. Please open kickflow in a separate window.

kickflow Settings

  1. Log in with an administrator account and select "Admin Center".kickflow03.png

  2. Click "Security" and select "Authentication Method".kickflow04.png


  3. Scroll down to "Single Sign-On (SSO) Settings". Click "Upload SAML Metadata" and click the clip button to upload the metadata.
    kickflow01.png
    kickflow02.png

  4. Copy and make a note of the "Assertion Consumer Service URL (ACS URL)" and "Entity ID".
    kickflow05.png


  5. In "JIT Provisioning Settings", turn on the "Enable JIT Provisioning" toggle.
    kickflow04.png

  6. Check "Single Sign-On" under "Authentication Methods Available to Users" and click "Save".
    kickflow07.png


    TrustLogin Admin Page Settings (Continued)

    1. Configure each item in "Service Provider Settings" with kickflow's information as follows.

      Login URL (blank field)

      Enter [Your Company ID].kickflow.com/startSso
      Note: You can also check kickflow's Company ID from the login URL.

      Entity ID Enter the "Entity ID" you noted from kickflow
      ACS URL to Service Enter the "Assertion Consumer Service URL (ACS URL)" you noted from kickflow

      kickflow.png

    2. Save the settings by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "kickflow (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "kickflow (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

kickflow SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in kickflow is required.

  • For the latest setup instructions, please check the manual provided by kickflow.

  • Single sign-on functionality is available on kickflow's Enterprise plan.
  • kickflow's SAML JIT only supports creating new accounts. Changes made in TrustLogin are not reflected, so administrators must manually update information in kickflow.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser


iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The app is available as a Progressive Web App (PWA) that can be installed from kickflow's website.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "kickflow (SAML)".
    kickflow01.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    kickflow02.png

    Now, switch to configuring kickflow. Please open kickflow in a separate window.

kickflow Settings

  1. Log in with an administrator account and select "Admin Center".kickflow03.png

  2. Click "Security" and select "Authentication Method".kickflow04.png


  3. Scroll down to "Single Sign-On (SSO) Settings". Click "Upload SAML Metadata" and click the clip button to upload the metadata.
    kickflow01.png
    kickflow02.png

  4. Copy and make a note of the "Assertion Consumer Service URL (ACS URL)" and "Entity ID".
    kickflow05.png


  5. In "JIT Provisioning Settings", turn on the "Enable JIT Provisioning" toggle.
    kickflow04.png

  6. Check "Single Sign-On" under "Authentication Methods Available to Users" and click "Save".
    kickflow07.png


    TrustLogin Admin Page Settings (Continued)

    1. Configure each item in "Service Provider Settings" with kickflow's information as follows.

      Login URL (blank field)

      Enter [Your Company ID].kickflow.com/startSso
      Note: You can also check kickflow's Company ID from the login URL.

      Entity ID Enter the "Entity ID" you noted from kickflow
      ACS URL to Service Enter the "Assertion Consumer Service URL (ACS URL)" you noted from kickflow

      kickflow.png

    2. Save the settings by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "kickflow (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "kickflow (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.