How to Configure SAML Authentication for Rakuraku Kintai

Item

Details

Pre-check

  • Prior configuration in Rakuraku Kintai is required.

  • The "SSO Authenticated ID" in the Rakuraku Kintai employee information must match the TrustLogin email address.
  • Please refer to the manual provided by Rakuraku Kintai for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Kintai (SAML)".
    02.png

  3. Note the value of the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png


Now, switch to configuring Rakuraku Kintai.
Do not click the "Register" button yet — open Rakuraku Kintai in a separate window.

Rakuraku Kintai Configuration

  1. Open "Attendance Management Screen > External Integration Settings > SSO Settings" and configure each item as follows.
    Finally, save by clicking the "Update" button.
    Use SSO Select "Use"
    IdP Login URL The "IdP URL" obtained from TrustLogin
    Redirect URL after Rakuraku Kintai logout https://portal.trustlogin.com/
    IdP Certificate The "Certificate" obtained from TrustLogin
    Rakuraku Kintai Metadata Download using the "Download" button

    04.png

  2. Open "Employee Settings" and open the edit screen for the target employee.
    Set the TrustLogin email address in "SSO Authenticated ID" and save by clicking the "Save" button.
    05.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from Rakuraku Kintai to the "Metadata" field in "Service Provider Settings".
    06.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Rakuraku Kintai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Kintai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Rakuraku Kintai

Item

Details

Pre-check

  • Prior configuration in Rakuraku Kintai is required.

  • The "SSO Authenticated ID" in the Rakuraku Kintai employee information must match the TrustLogin email address.
  • Please refer to the manual provided by Rakuraku Kintai for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Kintai (SAML)".
    02.png

  3. Note the value of the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png


Now, switch to configuring Rakuraku Kintai.
Do not click the "Register" button yet — open Rakuraku Kintai in a separate window.

Rakuraku Kintai Configuration

  1. Open "Attendance Management Screen > External Integration Settings > SSO Settings" and configure each item as follows.
    Finally, save by clicking the "Update" button.
    Use SSO Select "Use"
    IdP Login URL The "IdP URL" obtained from TrustLogin
    Redirect URL after Rakuraku Kintai logout https://portal.trustlogin.com/
    IdP Certificate The "Certificate" obtained from TrustLogin
    Rakuraku Kintai Metadata Download using the "Download" button

    04.png

  2. Open "Employee Settings" and open the edit screen for the target employee.
    Set the TrustLogin email address in "SSO Authenticated ID" and save by clicking the "Save" button.
    05.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from Rakuraku Kintai to the "Metadata" field in "Service Provider Settings".
    06.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Rakuraku Kintai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Kintai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.