Phrase Strings SAML JIT Setup Guide

Item

Details

Pre-check

  • Phrase Strings requires prior configuration.
  • SAML JIT for Phrase Strings only supports creating new accounts. Since changes made in TrustLogin are not reflected, the administrator must manually update information in Phrase Strings.
  • Please refer to the manual provided by Phrase Strings for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For instructions on how to configure this when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Phrase Strings (SAML)".
    Phrase

  3. Make a note of the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
    03.png


Now, switch to configuring Phrase Strings.
Do not click the "Register" button yet — open Phrase Strings in a separate window.

Phrase Strings Settings

  1. Open "Settings > Organization" from the icon in the upper right.
    Phrase

  2. Open the "SSO" tab and click "Enable SSO".
    Phrase

  3. In "Phrase Settings", configure the items as follows and make a note of the values.
    Automatic Provisioning Check the box
    Enforce SSO Configure according to your operational needs
    Single Sign-On Callback URL Copy and make a note of it
    Single Sign-On Subject Copy and make a note of it
    EmailAddress

    Phrase

  4. In "Identity Provider Settings", configure the items as follows, and finally save by clicking the "Save" button.
    Single Sign-On URL The "IdP URL" obtained from TrustLogin
    Issuer The "Issuer/Entity ID" obtained from TrustLogin
    X.509 Certificate Upload the TrustLogin certificate
    Fingerprint Algorithm SHA256

    Phrase

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Single Sign-On Subject" noted from Phrase Strings
    ACS URL to Service The "Single Sign-On Callback URL" noted from Phrase Strings

    Phrase

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase Strings (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Phrase Strings (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

First Login Method

When accessing via SAML for the first time, the screen below will be displayed. Check the displayed email address and click "Request Link".Phrase

A verification email will be sent to the new user's email address; click the link in the email. At that point, a TrustLogin error screen will be displayed, but the new user has already been created at the moment you clicked the link, so please close that screen and try logging in from My Page or the Phrase Strings login page.

Phrase Strings SAML JIT Setup Guide

Item

Details

Pre-check

  • Phrase Strings requires prior configuration.
  • SAML JIT for Phrase Strings only supports creating new accounts. Since changes made in TrustLogin are not reflected, the administrator must manually update information in Phrase Strings.
  • Please refer to the manual provided by Phrase Strings for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For instructions on how to configure this when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Phrase Strings (SAML)".
    Phrase

  3. Make a note of the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
    03.png


Now, switch to configuring Phrase Strings.
Do not click the "Register" button yet — open Phrase Strings in a separate window.

Phrase Strings Settings

  1. Open "Settings > Organization" from the icon in the upper right.
    Phrase

  2. Open the "SSO" tab and click "Enable SSO".
    Phrase

  3. In "Phrase Settings", configure the items as follows and make a note of the values.
    Automatic Provisioning Check the box
    Enforce SSO Configure according to your operational needs
    Single Sign-On Callback URL Copy and make a note of it
    Single Sign-On Subject Copy and make a note of it
    EmailAddress

    Phrase

  4. In "Identity Provider Settings", configure the items as follows, and finally save by clicking the "Save" button.
    Single Sign-On URL The "IdP URL" obtained from TrustLogin
    Issuer The "Issuer/Entity ID" obtained from TrustLogin
    X.509 Certificate Upload the TrustLogin certificate
    Fingerprint Algorithm SHA256

    Phrase

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Single Sign-On Subject" noted from Phrase Strings
    ACS URL to Service The "Single Sign-On Callback URL" noted from Phrase Strings

    Phrase

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase Strings (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Phrase Strings (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

First Login Method

When accessing via SAML for the first time, the screen below will be displayed. Check the displayed email address and click "Request Link".Phrase

A verification email will be sent to the new user's email address; click the link in the email. At that point, a TrustLogin error screen will be displayed, but the new user has already been created at the moment you clicked the link, so please close that screen and try logging in from My Page or the Phrase Strings login page.