How to Configure SAML Authentication for Stock

Item

Details

Prior Confirmation

  • Prior configuration in Stock is required.

  • You need to create an account in Stock in advance using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the manual provided by Narekan.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: If you are using client authentication, SSO is not available on iOS - Native App or Android - Native App.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "Stock (SAML)".
    Stock01.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to the Stock settings.
Without clicking the "Register" button, open Stock in a separate window.

Stock Settings

  1. Click "Settings > Change Team Settings".
    Stock03.png

  2. Open "Single Sign-On", configure it as follows, and click "Change".
    Entity ID Copy it and keep a note of it
    ACS URL Copy it and keep a note of it
    Upload XML File Upload the metadata you saved from TrustLogin
    Enable Single Sign-On Select "Migration Mode"
    Note: In "Migration Mode", logging in with a password is also possible. Once you have confirmed that team members can successfully log in via single sign-on, we recommend switching to "Single Sign-On Only" mode.

    Stock02.png

  3. After clicking the "Change" button, the "Single Sign-On URL" is displayed.
    This is the URL for SP-initiated SSO, so make a note of it if needed.
    Stock05.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" you noted from Stock
    ACS URL to Service The "ACS URL" you noted from Stock

    Narekan04.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Stock (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Stock (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Mobile App Login Method

Install the mobile app and select "Other > Single Sign-On".

stock (2).png

Enter your team's domain and click "Login" to be redirected to the TrustLogin login screen.
Note: Your team's domain is the "***" portion of the Stock URL "https://www.stock-app.jp/sso/***/sign-in".
Stock07.png

How to Configure SAML Authentication for Stock

Item

Details

Prior Confirmation

  • Prior configuration in Stock is required.

  • You need to create an account in Stock in advance using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the manual provided by Narekan.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: If you are using client authentication, SSO is not available on iOS - Native App or Android - Native App.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "Stock (SAML)".
    Stock01.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to the Stock settings.
Without clicking the "Register" button, open Stock in a separate window.

Stock Settings

  1. Click "Settings > Change Team Settings".
    Stock03.png

  2. Open "Single Sign-On", configure it as follows, and click "Change".
    Entity ID Copy it and keep a note of it
    ACS URL Copy it and keep a note of it
    Upload XML File Upload the metadata you saved from TrustLogin
    Enable Single Sign-On Select "Migration Mode"
    Note: In "Migration Mode", logging in with a password is also possible. Once you have confirmed that team members can successfully log in via single sign-on, we recommend switching to "Single Sign-On Only" mode.

    Stock02.png

  3. After clicking the "Change" button, the "Single Sign-On URL" is displayed.
    This is the URL for SP-initiated SSO, so make a note of it if needed.
    Stock05.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" you noted from Stock
    ACS URL to Service The "ACS URL" you noted from Stock

    Narekan04.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Stock (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Stock (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Mobile App Login Method

Install the mobile app and select "Other > Single Sign-On".

stock (2).png

Enter your team's domain and click "Login" to be redirected to the TrustLogin login screen.
Note: Your team's domain is the "***" portion of the Stock URL "https://www.stock-app.jp/sso/***/sign-in".
Stock07.png