How to Configure SAML Authentication for kickflow

Item

Details

Pre-check

  • Advance configuration in kickflow is required.

  • You must create an account in kickflow using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the documentation provided by kickflow.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on configuring provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The app is available as a Progressive Web App (PWA) that can be installed from the kickflow website.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Enterprise App" screen and select "kickflow (SAML)".
    kickflow01.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    kickflow02.png

    Now switch to the kickflow-side configuration. Please open kickflow in a separate window.

kickflow Settings

  1. Log in with an administrator account and select "Admin Center".kickflow03.png

  2. Click "Security" and select "Authentication Method".kickflow04.png


  3. Scroll down to "Single Sign-On (SSO) Settings". Click "Upload SAML Metadata", then click the paperclip button to upload the metadata.
    kickflow01.png
    kickflow02.png

  4. Copy and save the "Assertion Consumer Service URL (ACS URL)" and "Entity ID".
    kickflow05.png


  5. In "JIT Provisioning Settings", turn off the "Enable JIT Provisioning" toggle.
    kickflow03.png

  6. In "Authentication Methods Available to Users", check "Single Sign-On" and click "Save".
    kickflow07.png


    TrustLogin Admin Page Settings (Continued)

    1. Set each item under "Service Provider Settings" using the kickflow information as follows.

      Login URL field

      Enter [your company ID].kickflow.com/startSso
      Note: You can also check your kickflow company ID from the login URL.

      Entity ID Enter the "Entity ID" you copied from kickflow
      ACS URL for Service Enter the "Assertion Consumer Service URL (ACS URL)" you copied from kickflow

      kickflow.png

    2. Save the settings using the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "kickflow (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "kickflow (SAML)" app.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for kickflow

Item

Details

Pre-check

  • Advance configuration in kickflow is required.

  • You must create an account in kickflow using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the documentation provided by kickflow.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on configuring provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The app is available as a Progressive Web App (PWA) that can be installed from the kickflow website.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Enterprise App" screen and select "kickflow (SAML)".
    kickflow01.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    kickflow02.png

    Now switch to the kickflow-side configuration. Please open kickflow in a separate window.

kickflow Settings

  1. Log in with an administrator account and select "Admin Center".kickflow03.png

  2. Click "Security" and select "Authentication Method".kickflow04.png


  3. Scroll down to "Single Sign-On (SSO) Settings". Click "Upload SAML Metadata", then click the paperclip button to upload the metadata.
    kickflow01.png
    kickflow02.png

  4. Copy and save the "Assertion Consumer Service URL (ACS URL)" and "Entity ID".
    kickflow05.png


  5. In "JIT Provisioning Settings", turn off the "Enable JIT Provisioning" toggle.
    kickflow03.png

  6. In "Authentication Methods Available to Users", check "Single Sign-On" and click "Save".
    kickflow07.png


    TrustLogin Admin Page Settings (Continued)

    1. Set each item under "Service Provider Settings" using the kickflow information as follows.

      Login URL field

      Enter [your company ID].kickflow.com/startSso
      Note: You can also check your kickflow company ID from the login URL.

      Entity ID Enter the "Entity ID" you copied from kickflow
      ACS URL for Service Enter the "Assertion Consumer Service URL (ACS URL)" you copied from kickflow

      kickflow.png

    2. Save the settings using the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "kickflow (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "kickflow (SAML)" app.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.