How to Configure SAML Authentication for Salesforce

Item Details
Prerequisites
  • Advance configuration in Salesforce is required.
  • You must create an account in Salesforce using the same email address as your TrustLogin account.
  • You must configure a custom domain under "My Domain".
  • For the latest configuration steps, please refer to the manual provided by Salesforce.
Name ID Email address
Custom attribute Note: For instructions on how to configure custom attributes, click here
SP-side Settings Configured by the administrator
Request the SP to configure settings
Provisioning Supports provisioning via API (account management possible in TrustLogin)
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)
None (accounts are created in each system)
Note: For instructions on how to configure provisioning, click here
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Device Compatibility PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
Remarks Note: Due to a Salesforce specification change (effective Tuesday, February 3, 2026), an additional "Authentication Context Class" setting is now required.
For details on the items that require additional configuration, click here.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. Search on the "Corporate App Registration" screen and select "Salesforce (SAML)".
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png

At this point, switch over to the Salesforce settings.
Do not click the "Register" button yet — open the Salesforce admin page in a separate window.

Salesforce Configuration

Log in to the Salesforce admin page.

  1. Select "Identity > Single Sign-On Settings" from the menu.
    salesforce_saml_04.png

  2. Click the "Edit" button and check "SAML Enabled" to enable SAML.
    Click the "New from Metadata File" button.
    05.png
  3. Click the "Choose File" button and select and upload the metadata you downloaded from TrustLogin above.
    06.png
  4. Change "Service Provider Initiated Request Binding" to "HTTP POST",
    uncheck "Enable Single Logout", and click the "Save" button.
    07.png
  5. Click "Download Metadata" to download the metadata.
    09.png
  6. Open "Company Settings > My Domain" from the menu, scroll down to "Authentication Configuration", and click the "Edit" button.
    11.png
  7. Check "portal" (or the name you changed it to in step 4) under "Authentication Service" and click "Save".

    Please note that unchecking "Login Form" will disable login with the Salesforce account.
    12.png

    This will cause a "portal" button to appear on the Salesforce login screen, enabling SAML SSO.
    13.png

    Note: The "portal" label can be changed under "Identity > Single Sign-On Settings > Single Sign-On Configuration".
    14.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. In "Service Provider Settings", select "Authentication Context Class".2026-01-27_11-43-15.png
  2. Open the "Authentication Context Class" field, and select and configure one option from the list according to the authentication method you use.
    Note: "Authentication Context Class" is a setting that indicates the authentication strength (authentication method) required at the time of authentication.
    Due to a Salesforce specification change (effective Tuesday, February 3, 2026), an additional "Authentication Context Class" setting is now required.
    2026-02-10_10-56-47.png
  3. Click "Select Metadata" and upload the metadata you downloaded from Salesforce.
    2026-01-29_17-49-27.png
  4. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds It from My Page

Note: The administrator must configure the SAML app in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Salesforce (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Salesforce (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Salesforce

Item Details
Prerequisites
  • Advance configuration in Salesforce is required.
  • You must create an account in Salesforce using the same email address as your TrustLogin account.
  • You must configure a custom domain under "My Domain".
  • For the latest configuration steps, please refer to the manual provided by Salesforce.
Name ID Email address
Custom attribute Note: For instructions on how to configure custom attributes, click here
SP-side Settings Configured by the administrator
Request the SP to configure settings
Provisioning Supports provisioning via API (account management possible in TrustLogin)
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)
None (accounts are created in each system)
Note: For instructions on how to configure provisioning, click here
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Device Compatibility PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
Remarks Note: Due to a Salesforce specification change (effective Tuesday, February 3, 2026), an additional "Authentication Context Class" setting is now required.
For details on the items that require additional configuration, click here.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. Search on the "Corporate App Registration" screen and select "Salesforce (SAML)".
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png

At this point, switch over to the Salesforce settings.
Do not click the "Register" button yet — open the Salesforce admin page in a separate window.

Salesforce Configuration

Log in to the Salesforce admin page.

  1. Select "Identity > Single Sign-On Settings" from the menu.
    salesforce_saml_04.png

  2. Click the "Edit" button and check "SAML Enabled" to enable SAML.
    Click the "New from Metadata File" button.
    05.png
  3. Click the "Choose File" button and select and upload the metadata you downloaded from TrustLogin above.
    06.png
  4. Change "Service Provider Initiated Request Binding" to "HTTP POST",
    uncheck "Enable Single Logout", and click the "Save" button.
    07.png
  5. Click "Download Metadata" to download the metadata.
    09.png
  6. Open "Company Settings > My Domain" from the menu, scroll down to "Authentication Configuration", and click the "Edit" button.
    11.png
  7. Check "portal" (or the name you changed it to in step 4) under "Authentication Service" and click "Save".

    Please note that unchecking "Login Form" will disable login with the Salesforce account.
    12.png

    This will cause a "portal" button to appear on the Salesforce login screen, enabling SAML SSO.
    13.png

    Note: The "portal" label can be changed under "Identity > Single Sign-On Settings > Single Sign-On Configuration".
    14.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. In "Service Provider Settings", select "Authentication Context Class".2026-01-27_11-43-15.png
  2. Open the "Authentication Context Class" field, and select and configure one option from the list according to the authentication method you use.
    Note: "Authentication Context Class" is a setting that indicates the authentication strength (authentication method) required at the time of authentication.
    Due to a Salesforce specification change (effective Tuesday, February 3, 2026), an additional "Authentication Context Class" setting is now required.
    2026-02-10_10-56-47.png
  3. Click "Select Metadata" and upload the metadata you downloaded from Salesforce.
    2026-01-29_17-49-27.png
  4. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds It from My Page

Note: The administrator must configure the SAML app in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Salesforce (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Salesforce (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.