Channel Talk SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Channel Talk is required.

  • Domain ownership and verification are required to apply SAML.

  • Staff members with a verified domain are automatically invited to the channel on their first SAML SSO login.
  • For the latest setup instructions, please check the manual provided by Channel Talk.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Channel Talk (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate by clicking the "Get Certificate" button.
    03.png


Now, switch to configuring Channel Talk.
Do not click the "Register" button yet — open Channel Talk in a separate window.

Channel Talk Settings

  1. Open "Channel Settings > Security & Development > Security" and click the ">" mark to the right of "SAML SSO".
    チャネルトーク.png

  2. Enter your domain and click the "Add Domain" button.
    05.png

  3. Add the displayed value to your domain's DNS records, then click "Verify DNS Record".
    For instructions on configuring your domain's DNS records, please refer to your domain registrar's help documentation.
    DNS record updates can take up to approximately 72 hours to propagate, so if verification is not completed right away, please wait a while and then click "Verify DNS Record" again.
    06.png

    Once domain verification is complete, it will be displayed as a verified domain.
    07.png

  4. Configure each item in "SAML SSO Settings" as follows, and save by clicking the "Save" button.
    SSO URL Copy and note it down
    Entity ID Copy and note it down
    Identity Provider SSO URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Entity ID The "Issuer/Entity ID" obtained from TrustLogin

    Public certificate

    The contents of the "certificate" obtained from TrustLogin
    Allow email address login

    Configure according to your operational needs
    Note: We recommend keeping this ON until SAML SSO operation has been verified and users have been notified

    Automatically invite staff ON

    08_jit.png

  5. Turn the SAML SSO toggle ON to enable it.
    09.png


Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from Channel Talk
    ACS URL to Service The "SSO URL" obtained from Channel Talk

    10.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Channel Talk (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Channel Talk (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Channel Talk SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Channel Talk is required.

  • Domain ownership and verification are required to apply SAML.

  • Staff members with a verified domain are automatically invited to the channel on their first SAML SSO login.
  • For the latest setup instructions, please check the manual provided by Channel Talk.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Channel Talk (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate by clicking the "Get Certificate" button.
    03.png


Now, switch to configuring Channel Talk.
Do not click the "Register" button yet — open Channel Talk in a separate window.

Channel Talk Settings

  1. Open "Channel Settings > Security & Development > Security" and click the ">" mark to the right of "SAML SSO".
    チャネルトーク.png

  2. Enter your domain and click the "Add Domain" button.
    05.png

  3. Add the displayed value to your domain's DNS records, then click "Verify DNS Record".
    For instructions on configuring your domain's DNS records, please refer to your domain registrar's help documentation.
    DNS record updates can take up to approximately 72 hours to propagate, so if verification is not completed right away, please wait a while and then click "Verify DNS Record" again.
    06.png

    Once domain verification is complete, it will be displayed as a verified domain.
    07.png

  4. Configure each item in "SAML SSO Settings" as follows, and save by clicking the "Save" button.
    SSO URL Copy and note it down
    Entity ID Copy and note it down
    Identity Provider SSO URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Entity ID The "Issuer/Entity ID" obtained from TrustLogin

    Public certificate

    The contents of the "certificate" obtained from TrustLogin
    Allow email address login

    Configure according to your operational needs
    Note: We recommend keeping this ON until SAML SSO operation has been verified and users have been notified

    Automatically invite staff ON

    08_jit.png

  5. Turn the SAML SSO toggle ON to enable it.
    09.png


Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from Channel Talk
    ACS URL to Service The "SSO URL" obtained from Channel Talk

    10.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Channel Talk (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Channel Talk (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.