invoiceAgent Document Management SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in invoiceAgent Document Management is required.

  • Please refer to the manual provided by invoiceAgent Document Management for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    jit02.png
  3. Note the value of the "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Download Certificate" button.
    03.png

Now, switch to configuring invoiceAgent Document Management.
Do not click the "Register" button yet — open invoiceAgent Document Management in a separate window.

invoiceAgent Document Management Settings

  1. Open "Users and Groups > SAML Authentication" and click the "+" mark.
    04.png

  2. Configure each item as follows, and save by clicking the "OK" button.
    Domain Name Any name of your choice
    External Authentication Name Any name of your choice
    Enable SAML Authentication Check the box
    Note: This will disable regular password login.
    Target URL The "Identity Provider URL" obtained from TrustLogin
    Certificate The contents of the "Certificate" obtained from TrustLogin
    Download Metadata Click the button to download the metadata
    Add or Update Users Check the box and configure the group to be assigned when a user is added
    Add or Update Groups Check the box if you want to add or update domain groups

    jit05.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the "Metadata" obtained from invoiceAgent Document Management to "Metadata" under "Service Provider Settings".
    jit08.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.

    The third row only needs to be configured if you are adding or updating groups.
    For the group attribute value, select a group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    Value of ① below Unspecified Value of ① below

    Member > Member - Email Address
    Member > Member - Last Name
    Custom Attribute (*)

    Select the item you want to sync to the "Full Name" field in invoiceAgent Document Management's user information, from options such as those above

    Value of ② below Unspecified Value of ② below Member Member - Email Address
    Value of ③ below Unspecified Value of ③ below Group Select the group name you configured and add it using the "+" button
    ① http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    ② http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    ③ http://schemas.xmlsoap.org/claims/Group
    Note: Custom attributes require separate configuration. For how to configure custom attributes, see here


    jit09.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Note: If, for any reason, an error in the SAML authentication configuration prevents you from logging in to invoiceAgent Document Management,
you can enable password login by adding "?nosaml" to the end of the login URL.
Example: https://xxxxx.spa-cloud.com/spa/?nosaml

invoiceAgent Document Management SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in invoiceAgent Document Management is required.

  • Please refer to the manual provided by invoiceAgent Document Management for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    jit02.png
  3. Note the value of the "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Download Certificate" button.
    03.png

Now, switch to configuring invoiceAgent Document Management.
Do not click the "Register" button yet — open invoiceAgent Document Management in a separate window.

invoiceAgent Document Management Settings

  1. Open "Users and Groups > SAML Authentication" and click the "+" mark.
    04.png

  2. Configure each item as follows, and save by clicking the "OK" button.
    Domain Name Any name of your choice
    External Authentication Name Any name of your choice
    Enable SAML Authentication Check the box
    Note: This will disable regular password login.
    Target URL The "Identity Provider URL" obtained from TrustLogin
    Certificate The contents of the "Certificate" obtained from TrustLogin
    Download Metadata Click the button to download the metadata
    Add or Update Users Check the box and configure the group to be assigned when a user is added
    Add or Update Groups Check the box if you want to add or update domain groups

    jit05.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the "Metadata" obtained from invoiceAgent Document Management to "Metadata" under "Service Provider Settings".
    jit08.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.

    The third row only needs to be configured if you are adding or updating groups.
    For the group attribute value, select a group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    Value of ① below Unspecified Value of ① below

    Member > Member - Email Address
    Member > Member - Last Name
    Custom Attribute (*)

    Select the item you want to sync to the "Full Name" field in invoiceAgent Document Management's user information, from options such as those above

    Value of ② below Unspecified Value of ② below Member Member - Email Address
    Value of ③ below Unspecified Value of ③ below Group Select the group name you configured and add it using the "+" button
    ① http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    ② http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    ③ http://schemas.xmlsoap.org/claims/Group
    Note: Custom attributes require separate configuration. For how to configure custom attributes, see here


    jit09.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Note: If, for any reason, an error in the SAML authentication configuration prevents you from logging in to invoiceAgent Document Management,
you can enable password login by adding "?nosaml" to the end of the login URL.
Example: https://xxxxx.spa-cloud.com/spa/?nosaml