How to Configure SAML Authentication for Phrase TMS

Item

Details

Prerequisites

  • Phrase TMS requires prior configuration.
  • You must create an account in Phrase TMS using the same email address as your TrustLogin account.
  • For the latest configuration steps, please refer to the manual provided by Phrase TMS.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: Under verification

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Phrase TMS (SAML)".
    Phrase

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png

  4. Change the certificate's file extension to .cer or .crt, and open the certificate.

  5. Open the "Details" tab, copy the value shown in the "Thumbprint" field, and note it down.
    (You will enter this later as the fingerprint in Phrase TMS.)
    Phrase


Now, switch to configuring the Phrase TMS side.
Do not click the "Register" button yet — open Phrase TMS in a separate window.

Phrase TMS Configuration

  1. Log in to Phrase TMS, and from Settings, open "Single Sign-On Details".
    Phrase

  2. Check "Enable SSO for the account's organization."
    Phrase

  3. Configure the items as follows, and click "Save".
    Certificate fingerprint Enter the thumbprint value obtained from the TrustLogin certificate
    Certificate fingerprint algorithm SHA-1
    Issuer URL The "Issuer / Entity ID" obtained from TrustLogin
    SAML 2.0 Endpoint (HTTP) The "IdP URL" obtained from TrustLogin
    SLO Endpoint (HTTP) https://portal.trustlogin.com/
    User identification method EMAIL
    Domain name Specify any string (e.g., company name)

    Phrase

  4. Note down the value of the "Organization ID".
    Phrase


Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure the Entity ID and ACS URL under "Service Provider Settings" as follows.
    Note: The URL format differs depending on the data center you use. Enter the URL format that matches your environment.
    For "Organization ID," enter the value noted from Phrase TMS.
    Entity ID

    [EU Data Center]
    https://cloud.memsource.com/web/saml2Login/metadata/{Organization ID}

    [US Data Center]
    https://us.cloud.memsource.com/web/saml2Login/metadata/{Organization ID}

    Service ACS URL

    [EU Data Center]
    https://cloud.memsource.com/web/saml2Login/sacs/{Organization ID}

    [US Data Center]
    https://us.cloud.memsource.com/web/saml2Login/sacs/{Organization ID}

  2. Enter the "Organization ID".
    Phrase

  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase TMS (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Phrase TMS (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Phrase TMS

Item

Details

Prerequisites

  • Phrase TMS requires prior configuration.
  • You must create an account in Phrase TMS using the same email address as your TrustLogin account.
  • For the latest configuration steps, please refer to the manual provided by Phrase TMS.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: Under verification

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Phrase TMS (SAML)".
    Phrase

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png

  4. Change the certificate's file extension to .cer or .crt, and open the certificate.

  5. Open the "Details" tab, copy the value shown in the "Thumbprint" field, and note it down.
    (You will enter this later as the fingerprint in Phrase TMS.)
    Phrase


Now, switch to configuring the Phrase TMS side.
Do not click the "Register" button yet — open Phrase TMS in a separate window.

Phrase TMS Configuration

  1. Log in to Phrase TMS, and from Settings, open "Single Sign-On Details".
    Phrase

  2. Check "Enable SSO for the account's organization."
    Phrase

  3. Configure the items as follows, and click "Save".
    Certificate fingerprint Enter the thumbprint value obtained from the TrustLogin certificate
    Certificate fingerprint algorithm SHA-1
    Issuer URL The "Issuer / Entity ID" obtained from TrustLogin
    SAML 2.0 Endpoint (HTTP) The "IdP URL" obtained from TrustLogin
    SLO Endpoint (HTTP) https://portal.trustlogin.com/
    User identification method EMAIL
    Domain name Specify any string (e.g., company name)

    Phrase

  4. Note down the value of the "Organization ID".
    Phrase


Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure the Entity ID and ACS URL under "Service Provider Settings" as follows.
    Note: The URL format differs depending on the data center you use. Enter the URL format that matches your environment.
    For "Organization ID," enter the value noted from Phrase TMS.
    Entity ID

    [EU Data Center]
    https://cloud.memsource.com/web/saml2Login/metadata/{Organization ID}

    [US Data Center]
    https://us.cloud.memsource.com/web/saml2Login/metadata/{Organization ID}

    Service ACS URL

    [EU Data Center]
    https://cloud.memsource.com/web/saml2Login/sacs/{Organization ID}

    [US Data Center]
    https://us.cloud.memsource.com/web/saml2Login/sacs/{Organization ID}

  2. Enter the "Organization ID".
    Phrase

  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase TMS (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Phrase TMS (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.