DeepL SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in DeepL is required.

  • To introduce SSO in DeepL, you need to register for a team plan with 35 or more members on DeepL Pro Advanced/Ultimate.
  • Please refer to the manual provided by DeepL for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "DeepL (SAML)".
    DeepL.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

  4. Save by clicking the "Register" button.

DeepL Configuration

  1. Click the "Set up SSO" button in "Account > Team > Security" and set any SSO domain for your company. When you request an SSO domain for your company, DeepL will review it, and approval may take up to about 3 business days.
    05.png

  2. Once DeepL has approved your company's SSO domain, resume configuration.
    Click the "Set up SSO" button in "Single Sign-On (SSO)".
    06.png

  3. Configure as follows, then save at the end by clicking "Confirm".
    Authentication type SAML
    Configure SAML Select "Import from file" and upload the "metadata" downloaded from TrustLogin
    NameID policy format Email
    Assertion attribute: First name
    Firstname
    Assertion attribute: Last name Lastname
    Assertion attribute: Email address Email

    07_.png

TrustLogin Admin Page Settings (Continued)

  1. Resume the TrustLogin app configuration.
    (On the App screen in the Admin Page, search by app name → open the corresponding app's detail screen → edit the SAML app settings)

    In the empty field for "ACS URL to Service" in "Service Provider Settings", enter the "company SSO domain" you configured in DeepL.
    11.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "DeepL (SAML)", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "DeepL (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

DeepL Configuration (Testing and Enabling SSO)

  1. Before enabling SSO for the team, test SSO.
    At this time, the team's administrator account cannot use SSO, so please test with a different account.

    (Reference) Trying out the configuration before enabling SSO

  2. Once the test succeeds, click the "Enable SSO" button and enable SSO using the "Activate SSO" button in the dialog that opens. Please enable it only after you have finished notifying your users.
    Note: The login method for all users other than the team administrator account will become SAML SSO only.
    Note: Once SSO is enabled, it cannot be reverted, so please proceed with caution.08.png
    09.png

Login Method

① When Logging In with "DeepL (SAML)"

Running "DeepL (SAML)" from My Page or the browser extension will take you to the DeepL SSO login screen. After entering the "company SSO domain" and clicking the "Continue" button, login will be completed.
10.png

②When Using the Helper App

We also provide a helper app that can automatically fill in the "company SSO domain".
Search for it on the app search screen and register "【SAML Helper】DeepL" to use it.
Note: The helper app can only be used on PC browsers and Android - Standard Browser (Chrome).
DeepL01.png

DeepL SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in DeepL is required.

  • To introduce SSO in DeepL, you need to register for a team plan with 35 or more members on DeepL Pro Advanced/Ultimate.
  • Please refer to the manual provided by DeepL for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "DeepL (SAML)".
    DeepL.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

  4. Save by clicking the "Register" button.

DeepL Configuration

  1. Click the "Set up SSO" button in "Account > Team > Security" and set any SSO domain for your company. When you request an SSO domain for your company, DeepL will review it, and approval may take up to about 3 business days.
    05.png

  2. Once DeepL has approved your company's SSO domain, resume configuration.
    Click the "Set up SSO" button in "Single Sign-On (SSO)".
    06.png

  3. Configure as follows, then save at the end by clicking "Confirm".
    Authentication type SAML
    Configure SAML Select "Import from file" and upload the "metadata" downloaded from TrustLogin
    NameID policy format Email
    Assertion attribute: First name
    Firstname
    Assertion attribute: Last name Lastname
    Assertion attribute: Email address Email

    07_.png

TrustLogin Admin Page Settings (Continued)

  1. Resume the TrustLogin app configuration.
    (On the App screen in the Admin Page, search by app name → open the corresponding app's detail screen → edit the SAML app settings)

    In the empty field for "ACS URL to Service" in "Service Provider Settings", enter the "company SSO domain" you configured in DeepL.
    11.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "DeepL (SAML)", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "DeepL (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

DeepL Configuration (Testing and Enabling SSO)

  1. Before enabling SSO for the team, test SSO.
    At this time, the team's administrator account cannot use SSO, so please test with a different account.

    (Reference) Trying out the configuration before enabling SSO

  2. Once the test succeeds, click the "Enable SSO" button and enable SSO using the "Activate SSO" button in the dialog that opens. Please enable it only after you have finished notifying your users.
    Note: The login method for all users other than the team administrator account will become SAML SSO only.
    Note: Once SSO is enabled, it cannot be reverted, so please proceed with caution.08.png
    09.png

Login Method

① When Logging In with "DeepL (SAML)"

Running "DeepL (SAML)" from My Page or the browser extension will take you to the DeepL SSO login screen. After entering the "company SSO domain" and clicking the "Continue" button, login will be completed.
10.png

②When Using the Helper App

We also provide a helper app that can automatically fill in the "company SSO domain".
Search for it on the app search screen and register "【SAML Helper】DeepL" to use it.
Note: The helper app can only be used on PC browsers and Android - Standard Browser (Chrome).
DeepL01.png