How to Configure SAML Authentication for Qast

Item

Description

Prerequisites

  • Advance configuration is required on the Qast side.

  • You must create an account in Qast using the same email address as your TrustLogin account.
  • The single sign-on feature is available on Qast's Enterprise plan.
  • For the latest setup instructions, please refer to the manual provided by Qast.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side configuration

Configured by the administrator

Request the SP to configure it

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app in-app browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app in-app browser

Android - Native app

The Android native app is currently under investigation.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01_.png

  2. Search on the "Register Corporate App" screen and select "Qast (SAML)".
    Qast01.png

  3. From "Identity Provider Information", download the metadata via "Download Metadata".
    Qast02.png
  4. Fill in the blank fields under "Service Provider Settings" as follows.
    Login URL

    Qast's login URL

    Example: https://[team name].qast.jp/workspaces/1

    Entity ID

    The team name registered in Qast

    ACS URL for the service

    The team name registered in Qast

    Qast06.png

  5. Click the "Register" button.
  6. Click the "Add App" button on "My Page".
  7. On the "Register App" screen, select "Qast (SAML)" and click the "Next" button in the upper right of the screen.
  8. If you want to change the "Display Name", enter it, then click the "Register" button.

Qast Configuration

  1. Log in to Qast with an administrator account, then click the icon in the upper right of the screen to open My Page.
    Qast03.png

  2. From the left menu, go to "Security" and scroll down to "Single Sign-On". Click "Select XML File" and upload the metadata you downloaded from TrustLogin.
    Qast04.png

  3. Once the metadata is uploaded successfully, TrustLogin's information will be entered automatically.
    Confirm that the upload was successful, then click "Test" to run a connection test.
    Qast07.png

  4. If the connection test succeeds, the following pop-up will be displayed. Click "OK".
    Qast08.png
  5. When you check "Enabled", the following pop-up will be displayed. Click "OK" to enable single sign-on.
    (Note: Once single sign-on is enabled, all members currently logged in to Qast will be automatically logged out and required to log in via SSO. Be sure to confirm that the connection test completes successfully before enabling this.)
    Qast10.png

TrustLogin User Configuration

① When a user adds it from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Qast (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the "Qast (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, then click the "Register" button to add them.

How to Log In to Qast
Once single sign-on is configured in Qast, the following screen will be displayed at login.
Click "Log in with SSO" to log in.

Qast09.png

How to Configure SAML Authentication for Qast

Item

Description

Prerequisites

  • Advance configuration is required on the Qast side.

  • You must create an account in Qast using the same email address as your TrustLogin account.
  • The single sign-on feature is available on Qast's Enterprise plan.
  • For the latest setup instructions, please refer to the manual provided by Qast.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side configuration

Configured by the administrator

Request the SP to configure it

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app in-app browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app in-app browser

Android - Native app

The Android native app is currently under investigation.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01_.png

  2. Search on the "Register Corporate App" screen and select "Qast (SAML)".
    Qast01.png

  3. From "Identity Provider Information", download the metadata via "Download Metadata".
    Qast02.png
  4. Fill in the blank fields under "Service Provider Settings" as follows.
    Login URL

    Qast's login URL

    Example: https://[team name].qast.jp/workspaces/1

    Entity ID

    The team name registered in Qast

    ACS URL for the service

    The team name registered in Qast

    Qast06.png

  5. Click the "Register" button.
  6. Click the "Add App" button on "My Page".
  7. On the "Register App" screen, select "Qast (SAML)" and click the "Next" button in the upper right of the screen.
  8. If you want to change the "Display Name", enter it, then click the "Register" button.

Qast Configuration

  1. Log in to Qast with an administrator account, then click the icon in the upper right of the screen to open My Page.
    Qast03.png

  2. From the left menu, go to "Security" and scroll down to "Single Sign-On". Click "Select XML File" and upload the metadata you downloaded from TrustLogin.
    Qast04.png

  3. Once the metadata is uploaded successfully, TrustLogin's information will be entered automatically.
    Confirm that the upload was successful, then click "Test" to run a connection test.
    Qast07.png

  4. If the connection test succeeds, the following pop-up will be displayed. Click "OK".
    Qast08.png
  5. When you check "Enabled", the following pop-up will be displayed. Click "OK" to enable single sign-on.
    (Note: Once single sign-on is enabled, all members currently logged in to Qast will be automatically logged out and required to log in via SSO. Be sure to confirm that the connection test completes successfully before enabling this.)
    Qast10.png

TrustLogin User Configuration

① When a user adds it from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Qast (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the "Qast (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, then click the "Register" button to add them.

How to Log In to Qast
Once single sign-on is configured in Qast, the following screen will be displayed at login.
Click "Log in with SSO" to log in.

Qast09.png