How to Configure SAML Authentication for Freshworks

Item

Details

Pre-check

  • Advance configuration in Freshworks is required.

  • You must create an account in Freshworks using the same email address as your TrustLogin account.

  • Once you configure SSO in Freshworks, you can navigate from the Freshworks Admin Center to Freshworks products (Freshservice, Freshdesk, Freshsales, Freshchat, Freshcaller).
  • For the latest configuration steps, please refer to the manual provided by Freshworks.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: The native app was verified using the Freshdesk and Freshservice apps.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Freshworks (SAML)."
    02.png

    Note: If you use Freshservice, you can also configure SAML from the app named "Freshservice (SAML)."
    Freshservice.png

  3. Make a note of the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, let's move on to the settings on the Freshworks side.
Do not click the "Register" button yet — open Freshworks in a separate window.

Freshworks Settings

  1. Log in to Freshworks and click the ">" mark to the right of "Security > Default Login Method."
    04.png

  2. Click the "SSO Login" toggle.
    05.png

  3. Select "Your IdP > SAML."
    06.png

  4. Download the metadata from "Download Metadata."
    07.png

  5. Configure each item under "Map Information from IdP" as follows.
    Identity Provider Entity ID The "Issuer / Entity ID" obtained from TrustLogin
    SAML SSO URL The "IdP URL" obtained from TrustLogin
    Signature Options Signed response only
    Security Certificate The contents of the "certificate" obtained from TrustLogin

    08.png

  6. Save the settings with the "Configure SSO" button.

Now, let's go back to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. Configure the "Service Provider Settings" as follows.
    Redirect URL After Successful SP Authentication

    Your Freshworks organization URL

    Note: If you use Freshservice, you can specify the page to navigate to for SAML login (IdP-initiated) by specifying the following URL.

    Dashboard:
    https://[organization domain].freshservice.com/a/dashboard/default

    Support Portal:

    https://[organization domain].freshservice.com/support/home

    Metadata Upload the metadata obtained from Freshworks

    09.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Freshworks (SAML)," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Freshworks (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In via SSO Using the Native App

The following describes how to log in via SSO when using the Freshservice native app.

  1. Launch the app and enter "[organization domain].freshservice.com" in the "Support URL" field.
    Media.jpg

  2. Click "Sign in with SSO."
    If you are redirected to TrustLogin, log in to TrustLogin.
    Media2.jpg

  3. Click "Allow" to complete the login.
    Media3.jpg

How to Configure SAML Authentication for Freshworks

Item

Details

Pre-check

  • Advance configuration in Freshworks is required.

  • You must create an account in Freshworks using the same email address as your TrustLogin account.

  • Once you configure SSO in Freshworks, you can navigate from the Freshworks Admin Center to Freshworks products (Freshservice, Freshdesk, Freshsales, Freshchat, Freshcaller).
  • For the latest configuration steps, please refer to the manual provided by Freshworks.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: The native app was verified using the Freshdesk and Freshservice apps.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Freshworks (SAML)."
    02.png

    Note: If you use Freshservice, you can also configure SAML from the app named "Freshservice (SAML)."
    Freshservice.png

  3. Make a note of the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, let's move on to the settings on the Freshworks side.
Do not click the "Register" button yet — open Freshworks in a separate window.

Freshworks Settings

  1. Log in to Freshworks and click the ">" mark to the right of "Security > Default Login Method."
    04.png

  2. Click the "SSO Login" toggle.
    05.png

  3. Select "Your IdP > SAML."
    06.png

  4. Download the metadata from "Download Metadata."
    07.png

  5. Configure each item under "Map Information from IdP" as follows.
    Identity Provider Entity ID The "Issuer / Entity ID" obtained from TrustLogin
    SAML SSO URL The "IdP URL" obtained from TrustLogin
    Signature Options Signed response only
    Security Certificate The contents of the "certificate" obtained from TrustLogin

    08.png

  6. Save the settings with the "Configure SSO" button.

Now, let's go back to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. Configure the "Service Provider Settings" as follows.
    Redirect URL After Successful SP Authentication

    Your Freshworks organization URL

    Note: If you use Freshservice, you can specify the page to navigate to for SAML login (IdP-initiated) by specifying the following URL.

    Dashboard:
    https://[organization domain].freshservice.com/a/dashboard/default

    Support Portal:

    https://[organization domain].freshservice.com/support/home

    Metadata Upload the metadata obtained from Freshworks

    09.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Freshworks (SAML)," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Freshworks (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In via SSO Using the Native App

The following describes how to log in via SSO when using the Freshservice native app.

  1. Launch the app and enter "[organization domain].freshservice.com" in the "Support URL" field.
    Media.jpg

  2. Click "Sign in with SSO."
    If you are redirected to TrustLogin, log in to TrustLogin.
    Media2.jpg

  3. Click "Allow" to complete the login.
    Media3.jpg