CloudSign SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in CloudSign is required.
  • Using the SAML JIT feature requires a contract for CloudSign's Enterprise plan.

  • Enabling SAML SSO automatically makes the SAML JIT feature available.
  • Information linkage via the SAML JIT feature occurs only when an account is created.
  • Multiple domains are not supported.
  • For the latest setup instructions, please refer to the manual provided by CloudSign.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions for plans other than Enterprise, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Basic Information

The information that can be sent to CloudSign via the SAML JIT feature when an account is created is as follows.

Email address Required
Company name Optional
Full name Optional If left blank, the part of the linked email address before the "@" will be set as the name in CloudSign
Member Group ID Optional

Multiple member groups can be linked using comma separation
A maximum of 60 member groups can be linked per person

  • If linking the full name and Member Group ID is not required
    You can configure this using a SAML template.
    Please refer to the manual here and proceed with the configuration.

  • If you want to link the full name and Member Group ID
    You need to add a custom attribute to the TrustLogin member information.

    [TrustLogin Custom Attribute Configuration Example]
    Note: The attribute name can be anything you choose.
    Note: For the Member Group ID attribute value, set the CloudSign group ID.
    00.png

    You can check the CloudSign group ID on the CloudSign group details screen.
    00_1.png


    Please refer to the following pages for instructions on how to configure custom attributes.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    jit02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring CloudSign.
Do not click the "Register" button yet — open the CloudSign admin screen in a separate tab using an account with "SSO Administrator" privileges.

CloudSign Settings

  1. From the left menu of the admin screen, select "Team > SSO Settings".
    04.png

  2. From "Settings > Metadata File Settings > Select File", upload the metadata obtained from TrustLogin.
    05.png

  3. Make a note of the "Audience" and "ACS URL" under "Settings > Service Provider Information".
    Note: Be sure to keep this screen open and proceed with the next TrustLogin configuration.
    If you turn "ON" the "SSO Settings for Each Team" at the bottom of this screen before the TrustLogin configuration is complete, you will no longer be able to log in to the CloudSign admin screen.
    06.png

Now return to the TrustLogin settings page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL https://www.cloudsign.jp/login
    Entity ID The "Audience" obtained from CloudSign
    Name ID Format unspecified
    ACS URL to Service The "ACS URL" obtained from CloudSign

    jit04.png

  2. Configure "SAML Attribute Settings" as follows.
    The first row is required; rows 2-4 are optional and should be configured for any items you want to link.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    Value of (*) Email Value of (*)

    Member

    Member - Email Address

    organization Basic organization

    Member

    Member - Company Name

    username Basic username

    Custom Attribute

    The attribute name you configured

    member_group_ids Basic member_group_ids

    Custom Attribute

    The attribute name you configured

    (*) http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    jit05.png

  3. Save by clicking the "Register" button.

Now return to the CloudSign settings page again.

CloudSign Settings (Enabling SSO)

Turn ON the teams subject to SSO under "SSO Settings for Each Team".
08.png


TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log in to CloudSign

Logging in from CloudSign

  1. Access the CloudSign login page directly, or click the CloudSign SAML app in TrustLogin to be linked to the CloudSign login page.
    Enter your email address and click "Next".
    09.png

  2. Click the "Log In" button.
    cloudsign_10.png

    If you enter an email address that does not yet have an account in CloudSign, a new account will be created via the SAML JIT feature.
    jit09.png

  3. If you are already logged in to TrustLogin, you will be logged in to CloudSign.
    If you are not logged in to TrustLogin, the TrustLogin login screen will be displayed; after authenticating, you will be logged in to CloudSign.

How to Log in Using the Auxiliary App

When accessing via SAML authentication from the TrustLogin My Page or browser extension, you can register a separate "[For SAML Auxiliary Use] CloudSign" app to automatically fill in the email address and log in to CloudSign.
Note: The auxiliary app is only available on PC browsers and Android - Standard Browser (Chrome).

  1. Search on the "Register Company App" screen, select "[For SAML Auxiliary Use] CloudSign", and register it.
    10.png

  2. Click the "Add App" button on "My Page" and select "[For SAML Auxiliary Use] CloudSign".

  3. Enter the email address registered with CloudSign in the "Email Address" field and click the "Save" button.
    11.png

  4. Click the app from "My Page" or the "Browser Extension" and confirm that login succeeds.

CloudSign SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in CloudSign is required.
  • Using the SAML JIT feature requires a contract for CloudSign's Enterprise plan.

  • Enabling SAML SSO automatically makes the SAML JIT feature available.
  • Information linkage via the SAML JIT feature occurs only when an account is created.
  • Multiple domains are not supported.
  • For the latest setup instructions, please refer to the manual provided by CloudSign.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions for plans other than Enterprise, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Basic Information

The information that can be sent to CloudSign via the SAML JIT feature when an account is created is as follows.

Email address Required
Company name Optional
Full name Optional If left blank, the part of the linked email address before the "@" will be set as the name in CloudSign
Member Group ID Optional

Multiple member groups can be linked using comma separation
A maximum of 60 member groups can be linked per person

  • If linking the full name and Member Group ID is not required
    You can configure this using a SAML template.
    Please refer to the manual here and proceed with the configuration.

  • If you want to link the full name and Member Group ID
    You need to add a custom attribute to the TrustLogin member information.

    [TrustLogin Custom Attribute Configuration Example]
    Note: The attribute name can be anything you choose.
    Note: For the Member Group ID attribute value, set the CloudSign group ID.
    00.png

    You can check the CloudSign group ID on the CloudSign group details screen.
    00_1.png


    Please refer to the following pages for instructions on how to configure custom attributes.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    jit02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring CloudSign.
Do not click the "Register" button yet — open the CloudSign admin screen in a separate tab using an account with "SSO Administrator" privileges.

CloudSign Settings

  1. From the left menu of the admin screen, select "Team > SSO Settings".
    04.png

  2. From "Settings > Metadata File Settings > Select File", upload the metadata obtained from TrustLogin.
    05.png

  3. Make a note of the "Audience" and "ACS URL" under "Settings > Service Provider Information".
    Note: Be sure to keep this screen open and proceed with the next TrustLogin configuration.
    If you turn "ON" the "SSO Settings for Each Team" at the bottom of this screen before the TrustLogin configuration is complete, you will no longer be able to log in to the CloudSign admin screen.
    06.png

Now return to the TrustLogin settings page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL https://www.cloudsign.jp/login
    Entity ID The "Audience" obtained from CloudSign
    Name ID Format unspecified
    ACS URL to Service The "ACS URL" obtained from CloudSign

    jit04.png

  2. Configure "SAML Attribute Settings" as follows.
    The first row is required; rows 2-4 are optional and should be configured for any items you want to link.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    Value of (*) Email Value of (*)

    Member

    Member - Email Address

    organization Basic organization

    Member

    Member - Company Name

    username Basic username

    Custom Attribute

    The attribute name you configured

    member_group_ids Basic member_group_ids

    Custom Attribute

    The attribute name you configured

    (*) http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    jit05.png

  3. Save by clicking the "Register" button.

Now return to the CloudSign settings page again.

CloudSign Settings (Enabling SSO)

Turn ON the teams subject to SSO under "SSO Settings for Each Team".
08.png


TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log in to CloudSign

Logging in from CloudSign

  1. Access the CloudSign login page directly, or click the CloudSign SAML app in TrustLogin to be linked to the CloudSign login page.
    Enter your email address and click "Next".
    09.png

  2. Click the "Log In" button.
    cloudsign_10.png

    If you enter an email address that does not yet have an account in CloudSign, a new account will be created via the SAML JIT feature.
    jit09.png

  3. If you are already logged in to TrustLogin, you will be logged in to CloudSign.
    If you are not logged in to TrustLogin, the TrustLogin login screen will be displayed; after authenticating, you will be logged in to CloudSign.

How to Log in Using the Auxiliary App

When accessing via SAML authentication from the TrustLogin My Page or browser extension, you can register a separate "[For SAML Auxiliary Use] CloudSign" app to automatically fill in the email address and log in to CloudSign.
Note: The auxiliary app is only available on PC browsers and Android - Standard Browser (Chrome).

  1. Search on the "Register Company App" screen, select "[For SAML Auxiliary Use] CloudSign", and register it.
    10.png

  2. Click the "Add App" button on "My Page" and select "[For SAML Auxiliary Use] CloudSign".

  3. Enter the email address registered with CloudSign in the "Email Address" field and click the "Save" button.
    11.png

  4. Click the app from "My Page" or the "Browser Extension" and confirm that login succeeds.