How to Configure SAML Authentication for Phrase Suite

Item

Details

Prerequisites

  • Phrase Suite requires prior configuration.

  • You must create an account in Phrase Suite using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Phrase Suite.

Name ID

Email address

※1

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Phrase Suite (SAML)".
    PhraseSuite.png

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png


Now, switch to configuring the Phrase Suite side.
Do not click the "Register" button yet — open Phrase Suite in a separate window.

Phrase Suite Configuration

  1. From the icon at the top right, open "Settings > Organization".
    04.png

  2. Open the "SSO" tab and click "Enable SSO".
    05.png

  3. Configure each item as follows, and finally save by clicking the "Save" button.
    SAML metadata Download using the "Download Metadata" button
    Require users to sign in with SSO We recommend leaving this off during setup and testing.
    If you want SAML SSO to be the only login method, switch it ON when going live.
    GUID (Globally Unique Identifier) Specify any string (e.g., company name)
    (Used when logging in via SSO from the Phrase Suite login page)
    Identifier type Email address
    Login URL The "IdP URL" obtained from TrustLogin
    Issuer URL The "Issuer / Entity ID" obtained from TrustLogin
    Certificate Select "I have an Identity Provider certificate" and upload the certificate obtained from TrustLogin using the "Upload Certificate" button

    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Upload the metadata downloaded from Phrase Suite to the "Metadata" field under "Service Provider Settings".
    07.png


    Note 1: Steps for configuring "Name ID" when multiple users exist in Suite with the same email address

    If multiple users exist in Phrase Suite with the same email address (i.e., the email addresses of TMS and Strings users overlap but the usernames differ), you can log in to Suite via SSO by setting the username in a custom attribute.
    If you do not configure the custom attribute, the email address will not be a unique value, and you will not be able to log in to Suite via SSO.
    Set either the TMS or Strings username as the custom attribute.

    PhraseSuite01.png

    [TrustLogin Custom Attribute Configuration Example]
    Note: The attribute name can be anything.
    PhraseSuite02.png
    For configuration instructions, please refer to the pages below.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase Suite (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Phrase Suite (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Phrase Suite

Item

Details

Prerequisites

  • Phrase Suite requires prior configuration.

  • You must create an account in Phrase Suite using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Phrase Suite.

Name ID

Email address

※1

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Phrase Suite (SAML)".
    PhraseSuite.png

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png


Now, switch to configuring the Phrase Suite side.
Do not click the "Register" button yet — open Phrase Suite in a separate window.

Phrase Suite Configuration

  1. From the icon at the top right, open "Settings > Organization".
    04.png

  2. Open the "SSO" tab and click "Enable SSO".
    05.png

  3. Configure each item as follows, and finally save by clicking the "Save" button.
    SAML metadata Download using the "Download Metadata" button
    Require users to sign in with SSO We recommend leaving this off during setup and testing.
    If you want SAML SSO to be the only login method, switch it ON when going live.
    GUID (Globally Unique Identifier) Specify any string (e.g., company name)
    (Used when logging in via SSO from the Phrase Suite login page)
    Identifier type Email address
    Login URL The "IdP URL" obtained from TrustLogin
    Issuer URL The "Issuer / Entity ID" obtained from TrustLogin
    Certificate Select "I have an Identity Provider certificate" and upload the certificate obtained from TrustLogin using the "Upload Certificate" button

    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Upload the metadata downloaded from Phrase Suite to the "Metadata" field under "Service Provider Settings".
    07.png


    Note 1: Steps for configuring "Name ID" when multiple users exist in Suite with the same email address

    If multiple users exist in Phrase Suite with the same email address (i.e., the email addresses of TMS and Strings users overlap but the usernames differ), you can log in to Suite via SSO by setting the username in a custom attribute.
    If you do not configure the custom attribute, the email address will not be a unique value, and you will not be able to log in to Suite via SSO.
    Set either the TMS or Strings username as the custom attribute.

    PhraseSuite01.png

    [TrustLogin Custom Attribute Configuration Example]
    Note: The attribute name can be anything.
    PhraseSuite02.png
    For configuration instructions, please refer to the pages below.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase Suite (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Phrase Suite (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.