How to Configure SAML Authentication for HireRoo

 Item

Details 

Prior Confirmation

  • Prior configuration in HireRoo is required.

  • You must create an account in HireRoo using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by HireRoo.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "HireRoo (SAML)".
    02.png

  3. Note down the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Save by clicking the "Register" button.

HireRoo Configuration

  1. Log in with an administrator account and open "Company Settings > Security".
    Click the "Edit" button, then turn ON the "Enable SSO" toggle.
    04.png

  2. Configure each item as follows, then save by clicking the "Save" button.
    IdP Endpoint URL (SSO URL) The "Identity Provider URL" obtained from TrustLogin
    IdP Entity ID (issuer) The "Issuer/Entity ID" obtained from TrustLogin
    IdP Certificate (X.509 Certificate) The contents of the "Certificate" obtained from TrustLogin
    Target Domain Specify the domain of users subject to SAML SSO
    Enable Enforcement Mode

    Turn ON to restrict authentication methods other than SAML SSO
    Note: We recommend keeping this OFF until SAML configuration testing and user communication are complete. Also note that if turned ON, users outside the target domain will no longer be able to log in.


    05.png

TrustLogin User Configuration

① When Users Add the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "HireRoo (SAML)" and click the "Next" button at the top right of the screen.
  3. Enter a value if you want to change the "Display Name", then click the "Register" button.

② When an Administrator Adds Members

  1. Search for the "HireRoo (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

 

How to Log In

① Logging In with "HireRoo (SAML)"

Running "HireRoo (SAML)" from My Page or the browser extension will take you to the HireRoo login screen. Click "Single Sign-On", enter your "Company Email Address", and then click "Sign in with SSO (Single Sign-On)" to complete the login.
09.png
07.png

 

② Using the Helper App

We also provide a helper app that can automatically fill in your "Company Email Address".
Search for it on the app search screen and register "【SAML Helper】HireRoo" to use it.
Note: The helper app is only available on PC browsers.
08.png

 

 

How to Configure SAML Authentication for HireRoo

 Item

Details 

Prior Confirmation

  • Prior configuration in HireRoo is required.

  • You must create an account in HireRoo using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by HireRoo.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "HireRoo (SAML)".
    02.png

  3. Note down the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Save by clicking the "Register" button.

HireRoo Configuration

  1. Log in with an administrator account and open "Company Settings > Security".
    Click the "Edit" button, then turn ON the "Enable SSO" toggle.
    04.png

  2. Configure each item as follows, then save by clicking the "Save" button.
    IdP Endpoint URL (SSO URL) The "Identity Provider URL" obtained from TrustLogin
    IdP Entity ID (issuer) The "Issuer/Entity ID" obtained from TrustLogin
    IdP Certificate (X.509 Certificate) The contents of the "Certificate" obtained from TrustLogin
    Target Domain Specify the domain of users subject to SAML SSO
    Enable Enforcement Mode

    Turn ON to restrict authentication methods other than SAML SSO
    Note: We recommend keeping this OFF until SAML configuration testing and user communication are complete. Also note that if turned ON, users outside the target domain will no longer be able to log in.


    05.png

TrustLogin User Configuration

① When Users Add the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "HireRoo (SAML)" and click the "Next" button at the top right of the screen.
  3. Enter a value if you want to change the "Display Name", then click the "Register" button.

② When an Administrator Adds Members

  1. Search for the "HireRoo (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

 

How to Log In

① Logging In with "HireRoo (SAML)"

Running "HireRoo (SAML)" from My Page or the browser extension will take you to the HireRoo login screen. Click "Single Sign-On", enter your "Company Email Address", and then click "Sign in with SSO (Single Sign-On)" to complete the login.
09.png
07.png

 

② Using the Helper App

We also provide a helper app that can automatically fill in your "Company Email Address".
Search for it on the app search screen and register "【SAML Helper】HireRoo" to use it.
Note: The helper app is only available on PC browsers.
08.png