How to Configure SAML Authentication for HubSpot

Item

Details

Prerequisites

  • Preliminary configuration in HubSpot is required.

  • You must create an account in HubSpot using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by HubSpot.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "HubSpot (SAML)".
    HubSpot.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Click the "Register" button to save.

  5. Add the administrator who will perform testing as a member of the SAML app you created.
    For instructions on how to add members, see TrustLogin User Configuration below.

HubSpot Configuration

  1. Log in to HubSpot and open "Settings (gear icon in the upper right) > Account Defaults > Security > Set up single sign-on".
    04.png

  2. Configure each item under "Set up single sign-on" as shown below,
    and note down the values of "Audience URL" and "Sign-on URL".
    Identity Provider ID or Issuer URL The "Issuer/Entity ID" obtained from TrustLogin
    Identity Provider Single Sign-On URL The "IdP URL" obtained from TrustLogin
    X.509 Certificate The contents of the "certificate" obtained from TrustLogin

    05.png


Now go back to the TrustLogin configuration.
Do not click the "Confirm" button yet — leave this page open and return to the TrustLogin Admin Page in a separate window.


TrustLogin Admin Page Configuration (Continued)

  1. Resume the configuration on the TrustLogin side.
    (On the Apps screen in the Admin Page, search by app name → open the relevant app's detail screen → edit the SAML app settings)
    Configure each item under the service provider settings as shown below.
    Entity ID The "Audience URL" obtained from HubSpot
    ACS URL for the Service The "Sign-on URL" obtained from HubSpot

    06.png

  2. Click the "Register" button to save.

HubSpot Configuration (Continued)

  1. Return to the HubSpot page you had open, and click the "Confirm" button. This will run a connection check, and if it succeeds, the settings will be saved and SAML will be enabled.
    07.png

  2. If you want to restrict users' login method to SAML SSO only, check "Single sign-on (SSO) required".
    08.png

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "HubSpot (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "HubSpot (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for HubSpot

Item

Details

Prerequisites

  • Preliminary configuration in HubSpot is required.

  • You must create an account in HubSpot using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by HubSpot.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "HubSpot (SAML)".
    HubSpot.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Click the "Register" button to save.

  5. Add the administrator who will perform testing as a member of the SAML app you created.
    For instructions on how to add members, see TrustLogin User Configuration below.

HubSpot Configuration

  1. Log in to HubSpot and open "Settings (gear icon in the upper right) > Account Defaults > Security > Set up single sign-on".
    04.png

  2. Configure each item under "Set up single sign-on" as shown below,
    and note down the values of "Audience URL" and "Sign-on URL".
    Identity Provider ID or Issuer URL The "Issuer/Entity ID" obtained from TrustLogin
    Identity Provider Single Sign-On URL The "IdP URL" obtained from TrustLogin
    X.509 Certificate The contents of the "certificate" obtained from TrustLogin

    05.png


Now go back to the TrustLogin configuration.
Do not click the "Confirm" button yet — leave this page open and return to the TrustLogin Admin Page in a separate window.


TrustLogin Admin Page Configuration (Continued)

  1. Resume the configuration on the TrustLogin side.
    (On the Apps screen in the Admin Page, search by app name → open the relevant app's detail screen → edit the SAML app settings)
    Configure each item under the service provider settings as shown below.
    Entity ID The "Audience URL" obtained from HubSpot
    ACS URL for the Service The "Sign-on URL" obtained from HubSpot

    06.png

  2. Click the "Register" button to save.

HubSpot Configuration (Continued)

  1. Return to the HubSpot page you had open, and click the "Confirm" button. This will run a connection check, and if it succeeds, the settings will be saved and SAML will be enabled.
    07.png

  2. If you want to restrict users' login method to SAML SSO only, check "Single sign-on (SSO) required".
    08.png

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "HubSpot (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "HubSpot (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.