How to Configure SAML Authentication for @pocket

Item

Content

Prerequisites

  • @pocket requires prior configuration.

  • The @pocket user ID and the TrustLogin email address must match.

  • For the latest setup instructions, please refer to the manual provided by @pocket.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Verification Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the top right of the screen.
    01.png

  2. Search on the "Corporate App Registration" screen and select "@pocket (SAML)".
    02.png

  3. Note down the value of the "Identity Provider URL" in "Identity Provider Information", and download the "Certificate".
    03.png

  4. In the 3 blank fields under "Service Provider Settings", enter your organization's @pocket login URL.
    (Example) https://xxxxxx.at-pocket.com/xxxxxxxxxxxxxxx/
    04.png

  5. Save by clicking the "Register" button.

@pocket Configuration

  1. Log in to @pocket with a system administrator account and open "Administrator Settings".
    05.png

  2. Open "SAML Authentication Settings" and configure each item as follows.
    Use SAML Authentication Turn the toggle ON
    Require Use of SAML Authentication Turn ON/OFF according to your operational needs

    Note: If turned ON, the only login method will be SAML authentication, and login with an ID/password will no longer be possible.
    By accessing a URL with "?saml=off" appended to the end of the login URL, only system administrators can log in with an ID/password.
    IdP Login URL The "Identity Provider URL" obtained from TrustLogin
    IdP Public Key Certificate Using the paperclip icon on the right, upload the "Certificate" obtained from TrustLogin

    06.png

    When "Use SAML Authentication" is turned ON, a "Log in with External ID" button will appear on the login screen. When Require Use of SAML Authentication is enabled, the login screen will not be displayed.
    07.png


TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "@pocket (SAML)" and click the "Next" button in the top right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "@pocket (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for @pocket

Item

Content

Prerequisites

  • @pocket requires prior configuration.

  • The @pocket user ID and the TrustLogin email address must match.

  • For the latest setup instructions, please refer to the manual provided by @pocket.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Verification Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the top right of the screen.
    01.png

  2. Search on the "Corporate App Registration" screen and select "@pocket (SAML)".
    02.png

  3. Note down the value of the "Identity Provider URL" in "Identity Provider Information", and download the "Certificate".
    03.png

  4. In the 3 blank fields under "Service Provider Settings", enter your organization's @pocket login URL.
    (Example) https://xxxxxx.at-pocket.com/xxxxxxxxxxxxxxx/
    04.png

  5. Save by clicking the "Register" button.

@pocket Configuration

  1. Log in to @pocket with a system administrator account and open "Administrator Settings".
    05.png

  2. Open "SAML Authentication Settings" and configure each item as follows.
    Use SAML Authentication Turn the toggle ON
    Require Use of SAML Authentication Turn ON/OFF according to your operational needs

    Note: If turned ON, the only login method will be SAML authentication, and login with an ID/password will no longer be possible.
    By accessing a URL with "?saml=off" appended to the end of the login URL, only system administrators can log in with an ID/password.
    IdP Login URL The "Identity Provider URL" obtained from TrustLogin
    IdP Public Key Certificate Using the paperclip icon on the right, upload the "Certificate" obtained from TrustLogin

    06.png

    When "Use SAML Authentication" is turned ON, a "Log in with External ID" button will appear on the login screen. When Require Use of SAML Authentication is enabled, the login screen will not be displayed.
    07.png


TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "@pocket (SAML)" and click the "Next" button in the top right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "@pocket (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.