How to Configure SAML Authentication for InCircle

Item

Details

Prerequisites

  • Prior configuration on the InCircle side is required.

  • The InCircle user ID and the TrustLogin email address must match.

  • Mobile connections are only supported via the official app provided by InCircle.
  • For the latest setup instructions, please refer to the manual provided by InCircle.

NameID

Email address

Custom attribute Note: For instructions on configuring a custom attribute, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Device compatibility verification status

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Standard browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01_.png

  2. Search on the "Register Corporate App" screen and select "InCircle (SAML)".
    02.png

  3. Obtain the metadata from "Download Metadata" under Identity Provider Information, and click the "Register" button to save the app settings. Send it to your InCircle representative and request SAML configuration.
    03.png

  4. Once InCircle notifies you that the SAML configuration is complete, resume the configuration.
    (On the Admin Page's Apps screen, search by app name → open the corresponding app's details screen → change the SAML app settings)

    Open the metadata sent by InCircle in a text editor, extract the values of the "Entity ID" and "ACS URL for the service", and set them in the respective fields of the Service Provider configuration as shown below.
    Login URL InCircle login URL
    Note: Overwrite the value that was originally set.
    Example: https://xxxx.incircle.jp/xxxxxx/
    Entity ID

    Search the metadata for "entityID" and extract the value enclosed in quotation marks (" ") in [entityID="~"]

    Example: https://xxxx.incircle.jp:443/xxxxxx/saml/metadata

    ACS URL for the service

    Search the metadata for "AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"" and extract the value enclosed in quotation marks (" ") in [Location="~"]

    Example: https://xxxx.incircle.jp:443/xxxxxx/saml/SSO


    04.png
    05.png

  5. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "InCircle (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for and click the "InCircle (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Log In to InCircle

Click "Use Single Sign-On" on the login screen. If you are not logged in to TrustLogin, you will be redirected to the TrustLogin login screen; once you authenticate, login to InCircle will complete.

06.png

How to Configure SAML Authentication for InCircle

Item

Details

Prerequisites

  • Prior configuration on the InCircle side is required.

  • The InCircle user ID and the TrustLogin email address must match.

  • Mobile connections are only supported via the official app provided by InCircle.
  • For the latest setup instructions, please refer to the manual provided by InCircle.

NameID

Email address

Custom attribute Note: For instructions on configuring a custom attribute, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Device compatibility verification status

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Standard browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01_.png

  2. Search on the "Register Corporate App" screen and select "InCircle (SAML)".
    02.png

  3. Obtain the metadata from "Download Metadata" under Identity Provider Information, and click the "Register" button to save the app settings. Send it to your InCircle representative and request SAML configuration.
    03.png

  4. Once InCircle notifies you that the SAML configuration is complete, resume the configuration.
    (On the Admin Page's Apps screen, search by app name → open the corresponding app's details screen → change the SAML app settings)

    Open the metadata sent by InCircle in a text editor, extract the values of the "Entity ID" and "ACS URL for the service", and set them in the respective fields of the Service Provider configuration as shown below.
    Login URL InCircle login URL
    Note: Overwrite the value that was originally set.
    Example: https://xxxx.incircle.jp/xxxxxx/
    Entity ID

    Search the metadata for "entityID" and extract the value enclosed in quotation marks (" ") in [entityID="~"]

    Example: https://xxxx.incircle.jp:443/xxxxxx/saml/metadata

    ACS URL for the service

    Search the metadata for "AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"" and extract the value enclosed in quotation marks (" ") in [Location="~"]

    Example: https://xxxx.incircle.jp:443/xxxxxx/saml/SSO


    04.png
    05.png

  5. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "InCircle (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for and click the "InCircle (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Log In to InCircle

Click "Use Single Sign-On" on the login screen. If you are not logged in to TrustLogin, you will be redirected to the TrustLogin login screen; once you authenticate, login to InCircle will complete.

06.png