Salesforce SAML JIT Setup Guide

Item Details
Pre-check
  • Prior configuration in Salesforce is required.
  • You must configure a custom domain in "My Domain" in advance.
  • You can change profiles via SAML JIT, but note that changes resulting in a license downgrade are not allowed and will cause SSO to stop working.
  • Please refer to the manual provided by Salesforce for the latest configuration steps.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, see here
SP Configuration Configured by the administrator
Request SP to configure
Provisioning API-based Provisioning supported (account management available in TrustLogin)
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App

Notes

Note: Due to a Salesforce specification change (effective Tuesday, February 3, 2026), the "Authentication Context Class" requires additional configuration.
For details on the items that require additional configuration, please seehere.


Prerequisites

Set the Federation ID in Salesforce User Information

You need to set the "Federation ID" in the user information of existing Salesforce users.

Open "Setup > Users > [target user's detail screen]", click the "Edit" button, then set the same email address used in TrustLogin in the "Federation ID" field and save.
001.png

Add a Custom Attribute to TrustLogin Member Information

You need to add a custom attribute to the TrustLogin member information and register the Salesforce Profile ID.

  1. Obtain the "Profile ID" for each profile assigned in Salesforce.
    Open "Setup > Profiles > [target profile's detail screen]" and obtain the Profile ID from that page's URL. For details, refer to the Salesforce manual below.
    Reference: Find the Salesforce ID for a User or Profile
    002.png
  2. Configure a custom attribute in the TrustLogin member information to link the profile.
    Refer to the pages below for configuration steps.

    [TrustLogin Custom Attribute Configuration Example]
    003.png

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png
  2. Register the "Application Name" and "Icon" (optional).
    jit02.png
  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png

Now, switch to configuring the Salesforce side.
Do not click the "Register" button yet — open the Salesforce admin page in a separate window.

Salesforce Settings

Log in to the Salesforce admin page.

  1. Select "Identity > Single Sign-On Settings" from the menu.
    04.png
  2. Click the "Edit" button and check "SAML Enabled" to enable SAML.
    Click the "New from Metadata File" button.
    05.png
  3. Use the "Choose File" button to select and upload the metadata you downloaded from TrustLogin above.
    06.png
  4. Configure each item as follows and save by clicking the "Save" button.

    SAML Identity Type Select "Assertion contains the Federation ID from the User object"
    Service Provider Initiated Request Binding Change to "HTTP POST"
    Single Logout Enabled Uncheck
    User Provisioning Enabled Check
    User Provisioning Type Select "Standard"


    jit07.png

  5. Click "Download Metadata" to download the metadata.
    jit08.png
  6. Open "Company Settings > My Domain" from the menu, scroll down to "Authentication Configuration", and click the "Edit" button.
    11.png
  7. Check "portal" (or the name you changed it to in step 4) under "Authentication Service" and click "Save".

    Note: Unchecking "Login Form" will disable login with the Salesforce account, so please be careful.
    12.png

    This will display a "portal" button on the Salesforce login screen, enabling SAML SSO.
    13.png

    Note: The label "portal" can be changed under "Identity > Single Sign-On Settings > Single Sign-On Configuration".
    14.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. In "Service Provider Settings", select "Authentication Context Class".
    2026-01-27_14-38-13.png
  2. Open the "Authentication Context Class" item and select and configure one option from the list, according to the authentication method you use.
    Note: "Authentication Context Class" is a setting that indicates the authentication strength (authentication method) required at the time of authentication.
    Due to a Salesforce specification change (effective Tuesday, February 3, 2026), additional configuration of "Authentication Context Class" is now required.
    2026-02-10_10-56-47.png
  3. Click "Select Metadata" and upload the metadata you downloaded from Salesforce.
    2026-01-29_17-50-48.png
  4. Click "Add SAML Attribute" under "SAML Attribute Settings" to add an attribute, and configure it as follows.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    User.Email Basic User.Email ↔︎ Member Member - Email Address
    User.Username Basic User.Username ↔︎ Member Member - Email Address
    User.LastName Basic User.LastName ↔︎ Member Member - Last Name
    User.FirstName Basic User.FirstName ↔︎ Member Member - First Name
    User.ProfileId Basic User.ProfileId ↔︎ Custom Attribute The custom attribute you configured


    16.png

  5. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds a member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Salesforce SAML JIT Setup Guide

Item Details
Pre-check
  • Prior configuration in Salesforce is required.
  • You must configure a custom domain in "My Domain" in advance.
  • You can change profiles via SAML JIT, but note that changes resulting in a license downgrade are not allowed and will cause SSO to stop working.
  • Please refer to the manual provided by Salesforce for the latest configuration steps.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, see here
SP Configuration Configured by the administrator
Request SP to configure
Provisioning API-based Provisioning supported (account management available in TrustLogin)
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App

Notes

Note: Due to a Salesforce specification change (effective Tuesday, February 3, 2026), the "Authentication Context Class" requires additional configuration.
For details on the items that require additional configuration, please seehere.


Prerequisites

Set the Federation ID in Salesforce User Information

You need to set the "Federation ID" in the user information of existing Salesforce users.

Open "Setup > Users > [target user's detail screen]", click the "Edit" button, then set the same email address used in TrustLogin in the "Federation ID" field and save.
001.png

Add a Custom Attribute to TrustLogin Member Information

You need to add a custom attribute to the TrustLogin member information and register the Salesforce Profile ID.

  1. Obtain the "Profile ID" for each profile assigned in Salesforce.
    Open "Setup > Profiles > [target profile's detail screen]" and obtain the Profile ID from that page's URL. For details, refer to the Salesforce manual below.
    Reference: Find the Salesforce ID for a User or Profile
    002.png
  2. Configure a custom attribute in the TrustLogin member information to link the profile.
    Refer to the pages below for configuration steps.

    [TrustLogin Custom Attribute Configuration Example]
    003.png

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png
  2. Register the "Application Name" and "Icon" (optional).
    jit02.png
  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png

Now, switch to configuring the Salesforce side.
Do not click the "Register" button yet — open the Salesforce admin page in a separate window.

Salesforce Settings

Log in to the Salesforce admin page.

  1. Select "Identity > Single Sign-On Settings" from the menu.
    04.png
  2. Click the "Edit" button and check "SAML Enabled" to enable SAML.
    Click the "New from Metadata File" button.
    05.png
  3. Use the "Choose File" button to select and upload the metadata you downloaded from TrustLogin above.
    06.png
  4. Configure each item as follows and save by clicking the "Save" button.

    SAML Identity Type Select "Assertion contains the Federation ID from the User object"
    Service Provider Initiated Request Binding Change to "HTTP POST"
    Single Logout Enabled Uncheck
    User Provisioning Enabled Check
    User Provisioning Type Select "Standard"


    jit07.png

  5. Click "Download Metadata" to download the metadata.
    jit08.png
  6. Open "Company Settings > My Domain" from the menu, scroll down to "Authentication Configuration", and click the "Edit" button.
    11.png
  7. Check "portal" (or the name you changed it to in step 4) under "Authentication Service" and click "Save".

    Note: Unchecking "Login Form" will disable login with the Salesforce account, so please be careful.
    12.png

    This will display a "portal" button on the Salesforce login screen, enabling SAML SSO.
    13.png

    Note: The label "portal" can be changed under "Identity > Single Sign-On Settings > Single Sign-On Configuration".
    14.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. In "Service Provider Settings", select "Authentication Context Class".
    2026-01-27_14-38-13.png
  2. Open the "Authentication Context Class" item and select and configure one option from the list, according to the authentication method you use.
    Note: "Authentication Context Class" is a setting that indicates the authentication strength (authentication method) required at the time of authentication.
    Due to a Salesforce specification change (effective Tuesday, February 3, 2026), additional configuration of "Authentication Context Class" is now required.
    2026-02-10_10-56-47.png
  3. Click "Select Metadata" and upload the metadata you downloaded from Salesforce.
    2026-01-29_17-50-48.png
  4. Click "Add SAML Attribute" under "SAML Attribute Settings" to add an attribute, and configure it as follows.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    User.Email Basic User.Email ↔︎ Member Member - Email Address
    User.Username Basic User.Username ↔︎ Member Member - Email Address
    User.LastName Basic User.LastName ↔︎ Member Member - Last Name
    User.FirstName Basic User.FirstName ↔︎ Member Member - First Name
    User.ProfileId Basic User.ProfileId ↔︎ Custom Attribute The custom attribute you configured


    16.png

  5. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds a member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.