Shifter SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Shifter is required.

  • To use the single sign-on feature in Shifter, you need to sign up for a subscription.
  • If you delete all the Shifter roles and teams synced via SSO on the TrustLogin side, the last assigned role and team will remain on the Shifter side.
    If you want to remove them, please delete them manually.
  • Please refer to the manual provided by Shifter for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


Prerequisites

  • You need to configure a custom attribute in advance to link the Shifter role and team to the TrustLogin member information.
  • If you want to assign a role, set the attribute value to one of Administrator, Editor, or Contributor.
  • If you want to link a team, set the attribute value to the Shifter team ID you want the user to belong to. If you want the user to belong to multiple teams, set multiple IDs separated by commas.
    You can check the Shifter team ID from the URL of the team screen.
    Example: https://go.getshifter.io/teams/[Team ID]Shifter04.pngNote: Only configure this custom attribute if you want to assign a role and/or add the user to a specified team when the user is created.
    Note: The attribute name can be anything you choose.

    [TrustLogin Custom Attribute Configuration Example]Shifter03.png

    Please refer to the following pages for instructions on how to configure custom attributes.
  • Custom Attribute Setup (Individual Registration)
  • Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Configure the "Application Name" and "Icon" (optional).
    Shifter.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring Shifter.
Do not click the "Register" button yet — open Shifter in a separate window.

Shifter Settings

  1. Log in to Shifter and select "Account".
    Shifter05.png

  2. Under "Single Sign-On > Configuration > Single Sign-On Status", turn on the toggle to enable SSO. Note: If you have not signed up for the SAML authentication subscription, please sign up first.
    Enter the domain to be covered by SSO in "Organization Domain" and click "Update".
    Shifter06.png

  3. Copy the issued DNS record using the "Copy" button, and add the displayed DNS record to your domain. Once you have added it, click "Verify".
    Note: How to configure DNS records varies by domain registrar. Please refer to your domain registrar's help documentation. DNS record propagation may take up to 72 hours.
    Shifter07.png

  4. Once the DNS record has propagated and domain verification is complete, the "Parameters (registering connection information for your organization's directory system)" section will be displayed. Configure it as follows, and save by clicking "Update File".
    Audience Copy and make a note of it
    Callback URL Copy and make a note of it
    Login URL Copy and make a note of it
    Metadata Upload the "metadata" you noted from TrustLogin

    Shifter08.png

Now return to the TrustLogin admin page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" you noted from Shifter
    Sign SAML Response Check the box
    Value for Name ID Select "Member" - "email" (leave as default)
    Entity ID The "Audience" you noted from Shifter
    Name ID Format Select persistent
    ACS URL to Service The "Callback URL" you noted from Shifter

    Shifter01.png

  2. Click the "Add SAML Attribute" button in "SAML Attribute Settings" to add a row (attribute), and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    Unspecified

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    Member

    Member - Email Address

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userrole

    Unspecified

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userrole

    Custom Attribute

    The attribute name you configured
    (e.g., Shifterrole)

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userteams

    Unspecified

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userteams

    Custom Attribute

    The attribute name you configured
    (e.g., TeamID)


    Shifter02.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.


Login Method

① Logging in with the App You Created

When you click the custom app you created from "My Page" or the browser extension, you will be redirected to the Shifter login screen. Click "Are you Single Sign On?", enter your organization's email address, click "Login", and then click "corporate ID" to complete the login.
Shifter09.png
Shifter10.pngShifter11.png

②Using the Helper App

We also provide a helper app that can automatically fill in your "organization's email address".
Note: The helper app is only available on PC browsers.
Search for it on the app search screen and select "[SAML Helper] Shifter".
Shifter12.png

Register the "Login URL" you noted from Shifter in the "Login URL" field to use it.
Shifter13.png

Shifter SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Shifter is required.

  • To use the single sign-on feature in Shifter, you need to sign up for a subscription.
  • If you delete all the Shifter roles and teams synced via SSO on the TrustLogin side, the last assigned role and team will remain on the Shifter side.
    If you want to remove them, please delete them manually.
  • Please refer to the manual provided by Shifter for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


Prerequisites

  • You need to configure a custom attribute in advance to link the Shifter role and team to the TrustLogin member information.
  • If you want to assign a role, set the attribute value to one of Administrator, Editor, or Contributor.
  • If you want to link a team, set the attribute value to the Shifter team ID you want the user to belong to. If you want the user to belong to multiple teams, set multiple IDs separated by commas.
    You can check the Shifter team ID from the URL of the team screen.
    Example: https://go.getshifter.io/teams/[Team ID]Shifter04.pngNote: Only configure this custom attribute if you want to assign a role and/or add the user to a specified team when the user is created.
    Note: The attribute name can be anything you choose.

    [TrustLogin Custom Attribute Configuration Example]Shifter03.png

    Please refer to the following pages for instructions on how to configure custom attributes.
  • Custom Attribute Setup (Individual Registration)
  • Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Configure the "Application Name" and "Icon" (optional).
    Shifter.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring Shifter.
Do not click the "Register" button yet — open Shifter in a separate window.

Shifter Settings

  1. Log in to Shifter and select "Account".
    Shifter05.png

  2. Under "Single Sign-On > Configuration > Single Sign-On Status", turn on the toggle to enable SSO. Note: If you have not signed up for the SAML authentication subscription, please sign up first.
    Enter the domain to be covered by SSO in "Organization Domain" and click "Update".
    Shifter06.png

  3. Copy the issued DNS record using the "Copy" button, and add the displayed DNS record to your domain. Once you have added it, click "Verify".
    Note: How to configure DNS records varies by domain registrar. Please refer to your domain registrar's help documentation. DNS record propagation may take up to 72 hours.
    Shifter07.png

  4. Once the DNS record has propagated and domain verification is complete, the "Parameters (registering connection information for your organization's directory system)" section will be displayed. Configure it as follows, and save by clicking "Update File".
    Audience Copy and make a note of it
    Callback URL Copy and make a note of it
    Login URL Copy and make a note of it
    Metadata Upload the "metadata" you noted from TrustLogin

    Shifter08.png

Now return to the TrustLogin admin page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" you noted from Shifter
    Sign SAML Response Check the box
    Value for Name ID Select "Member" - "email" (leave as default)
    Entity ID The "Audience" you noted from Shifter
    Name ID Format Select persistent
    ACS URL to Service The "Callback URL" you noted from Shifter

    Shifter01.png

  2. Click the "Add SAML Attribute" button in "SAML Attribute Settings" to add a row (attribute), and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    Unspecified

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    Member

    Member - Email Address

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userrole

    Unspecified

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userrole

    Custom Attribute

    The attribute name you configured
    (e.g., Shifterrole)

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userteams

    Unspecified

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userteams

    Custom Attribute

    The attribute name you configured
    (e.g., TeamID)


    Shifter02.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.


Login Method

① Logging in with the App You Created

When you click the custom app you created from "My Page" or the browser extension, you will be redirected to the Shifter login screen. Click "Are you Single Sign On?", enter your organization's email address, click "Login", and then click "corporate ID" to complete the login.
Shifter09.png
Shifter10.pngShifter11.png

②Using the Helper App

We also provide a helper app that can automatically fill in your "organization's email address".
Note: The helper app is only available on PC browsers.
Search for it on the app search screen and select "[SAML Helper] Shifter".
Shifter12.png

Register the "Login URL" you noted from Shifter in the "Login URL" field to use it.
Shifter13.png