How to Configure SAML Authentication for TOKIUM

Item

Details

Prior Confirmation

  • Prior configuration in TOKIUM is required.

  • You must create a TOKIUM account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please check the manual provided by TOKIUM.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "TOKIUM (SAML)".
    TOKIUM00.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png


Now, switch to configuring TOKIUM.
Do not click the "Register" button yet — open TOKIUM in a separate window.

TOKIUM Settings

  1. After logging in to TOKIUM, open the "System Settings" dropdown and select "Security".
    TOKIUM01.png

  2. Enter your "Subdomain" and click "Save" to register the subdomain.
    TOKIUM02.png

  3. After registering the subdomain, make a note of the URL displayed in "Login URL".
    (You will use this later when configuring TrustLogin.)
    TOKIUM03.png

  4. Click "SAML Settings > Create".
    TOKIUM04.png

  5. Enter a "Setting Name" and "Description", then click "Create".
    Note: You may enter any name or description you like.
    TOKIUM05.png

  6. Select the SAML setting name you created in step 5 (in this example, "TrustLogin").
    TOKIUM06.png

  7. Make a note of the "Entity ID", "ACS URL", and "Logout URL" under "Service Provider Information". (You will use these later when configuring TrustLogin.)
    TOKIUM07.png

  8. Select "SAML Settings > Edit". Click "Choose File", upload the metadata you saved from TrustLogin, and click "Save".
    TOKIUM08.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Login URL" you noted from TOKIUM
    Entity ID The "Entity ID" you noted from TOKIUM
    ACS URL to Service The "ACS URL" you noted from TOKIUM
    Logout URL The "Logout URL" you noted from TOKIUM
    Note: Single logout is planned for a future release, but is not currently implemented and does not function

    TOKIUM09.png
  2. Save the settings by clicking the "Register" button.

  3. Add the user who is currently performing the SAML configuration to the "TOKIUM (SAML)" app.
    Search for the "TOKIUM (SAML)" app from "Admin Page > App", and add the user via "Add Member".

TOKIUM Settings (Continued)

  1. Verify that the SAML settings configured so far are working correctly by testing the connection. Return to the SAML settings in TOKIUM, and under "Check SAML Settings", click "Verify Settings".
    TOKIUM10.png

  2. If the connection is successful, "SAML connection succeeded" will be displayed.
    TOKIUM11.png

  3. After confirming the connection is successful, turn on "Enable SAML Authentication" to activate it.TOKIUM12.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "TOKIUM (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "TOKIUM (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In

  1. When you access TrustLogin's My Page or TOKIUM's login URL, the "Setting Name" of the IdP configured in TOKIUM will be displayed. Select the IdP you want to use to log in via SAML, and log in.
    TOKIUM13.png


SSO Authentication Method for the Native App

TOKIUM supports a native app. If you use the native app, you can log in using the method described below.

  1. Download and open the TOKIUM native app.


  2. Select "Other Login Methods".
    TOKIUM16.png


  3. Select "Use Subdomain".
    TOKIUM20.png

  4. Enter the subdomain you configured in TOKIUM and click "Next".
    TOKIUM19.png

  5. Select "Other Login Methods" again.
    TOKIUM18.png

  6. The configured IdP name will be displayed. Select the IdP name you want to use to log in, and log in.
    TOKIUM17.png

How to Configure SAML Authentication for TOKIUM

Item

Details

Prior Confirmation

  • Prior configuration in TOKIUM is required.

  • You must create a TOKIUM account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please check the manual provided by TOKIUM.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "TOKIUM (SAML)".
    TOKIUM00.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png


Now, switch to configuring TOKIUM.
Do not click the "Register" button yet — open TOKIUM in a separate window.

TOKIUM Settings

  1. After logging in to TOKIUM, open the "System Settings" dropdown and select "Security".
    TOKIUM01.png

  2. Enter your "Subdomain" and click "Save" to register the subdomain.
    TOKIUM02.png

  3. After registering the subdomain, make a note of the URL displayed in "Login URL".
    (You will use this later when configuring TrustLogin.)
    TOKIUM03.png

  4. Click "SAML Settings > Create".
    TOKIUM04.png

  5. Enter a "Setting Name" and "Description", then click "Create".
    Note: You may enter any name or description you like.
    TOKIUM05.png

  6. Select the SAML setting name you created in step 5 (in this example, "TrustLogin").
    TOKIUM06.png

  7. Make a note of the "Entity ID", "ACS URL", and "Logout URL" under "Service Provider Information". (You will use these later when configuring TrustLogin.)
    TOKIUM07.png

  8. Select "SAML Settings > Edit". Click "Choose File", upload the metadata you saved from TrustLogin, and click "Save".
    TOKIUM08.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Login URL" you noted from TOKIUM
    Entity ID The "Entity ID" you noted from TOKIUM
    ACS URL to Service The "ACS URL" you noted from TOKIUM
    Logout URL The "Logout URL" you noted from TOKIUM
    Note: Single logout is planned for a future release, but is not currently implemented and does not function

    TOKIUM09.png
  2. Save the settings by clicking the "Register" button.

  3. Add the user who is currently performing the SAML configuration to the "TOKIUM (SAML)" app.
    Search for the "TOKIUM (SAML)" app from "Admin Page > App", and add the user via "Add Member".

TOKIUM Settings (Continued)

  1. Verify that the SAML settings configured so far are working correctly by testing the connection. Return to the SAML settings in TOKIUM, and under "Check SAML Settings", click "Verify Settings".
    TOKIUM10.png

  2. If the connection is successful, "SAML connection succeeded" will be displayed.
    TOKIUM11.png

  3. After confirming the connection is successful, turn on "Enable SAML Authentication" to activate it.TOKIUM12.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "TOKIUM (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "TOKIUM (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In

  1. When you access TrustLogin's My Page or TOKIUM's login URL, the "Setting Name" of the IdP configured in TOKIUM will be displayed. Select the IdP you want to use to log in via SAML, and log in.
    TOKIUM13.png


SSO Authentication Method for the Native App

TOKIUM supports a native app. If you use the native app, you can log in using the method described below.

  1. Download and open the TOKIUM native app.


  2. Select "Other Login Methods".
    TOKIUM16.png


  3. Select "Use Subdomain".
    TOKIUM20.png

  4. Enter the subdomain you configured in TOKIUM and click "Next".
    TOKIUM19.png

  5. Select "Other Login Methods" again.
    TOKIUM18.png

  6. The configured IdP name will be displayed. Select the IdP name you want to use to log in, and log in.
    TOKIUM17.png