Notion SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Notion is required.

  • SAML SSO is available on the Business plan or Enterprise plan.
  • Domain ownership is required, and SSO is only available for user accounts on verified domains.
  • Notion's SAML JIT only supports creating new users. Since updating information in TrustLogin does not update it in Notion, please make information changes manually in Notion.
  • If a member is removed from a workspace, they will not be automatically re-added to the workspace even if they subsequently log in again via SAML. To re-add a removed member, the workspace owner must add them manually.
  • For the latest setup instructions, please check the manual provided by Notion.

Email address

Custom attribute Note: For how to configure custom attributes, click here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, click here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App



TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "Notion (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png
  4. Save by clicking the "Register" button.

Notion Settings

  1. After logging in with an account that has workspace owner permissions, open "Settings" > "Settings" and, if a domain is set under "Allowed email domains", remove it and save.
    04.png
    06.png

  2. Open "Authentication and provisioning" and click "+Add domain" under domain management.07.png

  3. Enter the domain name to verify and click "Next".
    Follow the displayed instructions to configure the domain's DNS records. For instructions on how to configure DNS records, please refer to your domain registrar's help documentation. DNS record updates may take up to approximately 72 hours to propagate.

    08.png

  4. After the DNS record has been updated, click "Verify", and a notification requesting confirmation of the DNS record will be sent to Notion. Once verification is complete, the domain's status will be displayed as "Verified".
    09.png
    10.png

  5. Configure each item of SAML Single Sign-On (SSO) as follows.
    Enable SAML SSO ON
    Edit SAML SSO configuration Click the button and, in the window that opens,
    1. Make a note of the "Assertion Consumer Service (ACS) URL" value.

    2. Check "Identity provider metadata XML" under "Identity provider details", open the metadata obtained from TrustLogin in a text editor, copy its entire contents, and paste it in.
      12.png
    Login method Configure this according to your operational needs.
    Note: Selecting "SAML SSO only" will disable login using a Notion account, etc. Please be careful when selecting this option.
    Automatic account creation ON

    11_1.png

  6. Make a note of the value under "Setup information > Workspace ID".
    13.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Resume the TrustLogin configuration.
    (On the app screen in the Admin Page, search by app name → open the relevant app's detail screen → change the SAML app settings)

  2. Configure "Service Provider Settings" as follows.
    Login URL The "Assertion Consumer Service (ACS) URL" obtained from Notion
    Entity ID The "Workspace ID" obtained from Notion
    ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Notion

    14.png
  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Notion (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Notion (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Notion SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Notion is required.

  • SAML SSO is available on the Business plan or Enterprise plan.
  • Domain ownership is required, and SSO is only available for user accounts on verified domains.
  • Notion's SAML JIT only supports creating new users. Since updating information in TrustLogin does not update it in Notion, please make information changes manually in Notion.
  • If a member is removed from a workspace, they will not be automatically re-added to the workspace even if they subsequently log in again via SAML. To re-add a removed member, the workspace owner must add them manually.
  • For the latest setup instructions, please check the manual provided by Notion.

Email address

Custom attribute Note: For how to configure custom attributes, click here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, click here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App



TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "Notion (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png
  4. Save by clicking the "Register" button.

Notion Settings

  1. After logging in with an account that has workspace owner permissions, open "Settings" > "Settings" and, if a domain is set under "Allowed email domains", remove it and save.
    04.png
    06.png

  2. Open "Authentication and provisioning" and click "+Add domain" under domain management.07.png

  3. Enter the domain name to verify and click "Next".
    Follow the displayed instructions to configure the domain's DNS records. For instructions on how to configure DNS records, please refer to your domain registrar's help documentation. DNS record updates may take up to approximately 72 hours to propagate.

    08.png

  4. After the DNS record has been updated, click "Verify", and a notification requesting confirmation of the DNS record will be sent to Notion. Once verification is complete, the domain's status will be displayed as "Verified".
    09.png
    10.png

  5. Configure each item of SAML Single Sign-On (SSO) as follows.
    Enable SAML SSO ON
    Edit SAML SSO configuration Click the button and, in the window that opens,
    1. Make a note of the "Assertion Consumer Service (ACS) URL" value.

    2. Check "Identity provider metadata XML" under "Identity provider details", open the metadata obtained from TrustLogin in a text editor, copy its entire contents, and paste it in.
      12.png
    Login method Configure this according to your operational needs.
    Note: Selecting "SAML SSO only" will disable login using a Notion account, etc. Please be careful when selecting this option.
    Automatic account creation ON

    11_1.png

  6. Make a note of the value under "Setup information > Workspace ID".
    13.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Resume the TrustLogin configuration.
    (On the app screen in the Admin Page, search by app name → open the relevant app's detail screen → change the SAML app settings)

  2. Configure "Service Provider Settings" as follows.
    Login URL The "Assertion Consumer Service (ACS) URL" obtained from Notion
    Entity ID The "Workspace ID" obtained from Notion
    ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Notion

    14.png
  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Notion (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Notion (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.