How to Configure SAML Authentication for Pipedrive

Item

Details

Pre-check

  • Advance configuration on the Pipedrive side is required.

  • You must create a Pipedrive account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Pipedrive.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each individual system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Pipedrive (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to configuring the Pipedrive side.
Do not click the "Register" button yet — open Pipedrive in a separate window.

Pipedrive Configuration

  1. From the menu under the icon in the upper right, select "Company settings".
    04.png

  2. Open "Single Sign-On".05.png

  3. Configure each item under "SAML configuration for Pipedrive" as follows.
    Issuer The "Issuer/Entity ID" obtained from TrustLogin
    Single sign-on (SSO) URL The "IdP URL" obtained from TrustLogin
    X.509 certificate The contents of the "certificate" obtained from TrustLogin

    06.png

  4. Under "SAML configuration for your IDP", copy the "Single sign-on (SSO) URL" using the "Copy to clipboard" button.
    07.png

Return to the TrustLogin configuration page.
Leave the Pipedrive page open as is.

TrustLogin Admin Page Configuration (Continued)

  1. Resume the TrustLogin configuration.
    Under "Service Provider Settings > ACS URL for Service", paste the "Single sign-on (SSO) URL" you copied from Pipedrive.
    08.png

  2. Click the "Register" button to save.

  3. To perform a connection test in Pipedrive, add the administrator who will run the test as a member of the SAML app you created.
    For instructions on how to add a member, see TrustLogin User Settings below.

Return to Pipedrive again.

Pipedrive Configuration (Continued)

  1. Click the "Save & Test" button to perform a connection test.
    09.png

  2. When the message indicating the SSO login test was successful appears, click "Enable SSO/SAML for users?".
    10.png

  3. SSO has been enabled for all users.
    At this point, users can log in using either their ID/password or SAML SSO.

    Note: Turning on "Enforce SSO login" will restrict login to SAML SSO only.
    11.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Pipedrive (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Pipedrive (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Pipedrive

Item

Details

Pre-check

  • Advance configuration on the Pipedrive side is required.

  • You must create a Pipedrive account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Pipedrive.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each individual system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Pipedrive (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to configuring the Pipedrive side.
Do not click the "Register" button yet — open Pipedrive in a separate window.

Pipedrive Configuration

  1. From the menu under the icon in the upper right, select "Company settings".
    04.png

  2. Open "Single Sign-On".05.png

  3. Configure each item under "SAML configuration for Pipedrive" as follows.
    Issuer The "Issuer/Entity ID" obtained from TrustLogin
    Single sign-on (SSO) URL The "IdP URL" obtained from TrustLogin
    X.509 certificate The contents of the "certificate" obtained from TrustLogin

    06.png

  4. Under "SAML configuration for your IDP", copy the "Single sign-on (SSO) URL" using the "Copy to clipboard" button.
    07.png

Return to the TrustLogin configuration page.
Leave the Pipedrive page open as is.

TrustLogin Admin Page Configuration (Continued)

  1. Resume the TrustLogin configuration.
    Under "Service Provider Settings > ACS URL for Service", paste the "Single sign-on (SSO) URL" you copied from Pipedrive.
    08.png

  2. Click the "Register" button to save.

  3. To perform a connection test in Pipedrive, add the administrator who will run the test as a member of the SAML app you created.
    For instructions on how to add a member, see TrustLogin User Settings below.

Return to Pipedrive again.

Pipedrive Configuration (Continued)

  1. Click the "Save & Test" button to perform a connection test.
    09.png

  2. When the message indicating the SSO login test was successful appears, click "Enable SSO/SAML for users?".
    10.png

  3. SSO has been enabled for all users.
    At this point, users can log in using either their ID/password or SAML SSO.

    Note: Turning on "Enforce SSO login" will restrict login to SAML SSO only.
    11.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Pipedrive (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Pipedrive (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.