| Item | Details | |
|---|---|---|
| Prerequisites |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For instructions on how to configure custom attributes, click here | ||
| SP-side Settings | 〇 | Configured by the administrator |
| Request the SP to configure settings | ||
| Provisioning | Supports provisioning via API (account management possible in TrustLogin) | |
| Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) | ||
| 〇 |
None (accounts are created in each system) Note: For instructions on how to configure provisioning, click here |
|
| Access Method | 〇 | SP-Initiated SSO |
| 〇 | IdP-Initiated SSO | |
| Verified Device Compatibility | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Standard Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App In-App Browser | |
| 〇 | iOS - Native App | |
| 〇 | Android - Standard Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App In-App Browser | |
| 〇 | Android - Native App | |
| Remarks |
Note: Due to a Salesforce specification change (effective Tuesday, February 3, 2026), an additional "Authentication Context Class" setting is now required. For details on the items that require additional configuration, click here. |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Corporate App Registration" screen and select "Salesforce (SAML)".
- Download the metadata from "Download Metadata" under "Identity Provider Information".
At this point, switch over to the Salesforce settings.
Do not click the "Register" button yet — open the Salesforce admin page in a separate window.
Salesforce Configuration
Log in to the Salesforce admin page.
- Select "Identity > Single Sign-On Settings" from the menu.
- Click the "Edit" button and check "SAML Enabled" to enable SAML.
Click the "New from Metadata File" button.
- Click the "Choose File" button and select and upload the metadata you downloaded from TrustLogin above.
- Change "Service Provider Initiated Request Binding" to "HTTP POST",
uncheck "Enable Single Logout", and click the "Save" button.
- Click "Download Metadata" to download the metadata.
- Open "Company Settings > My Domain" from the menu, scroll down to "Authentication Configuration", and click the "Edit" button.
- Check "portal" (or the name you changed it to in step 4) under "Authentication Service" and click "Save".
Please note that unchecking "Login Form" will disable login with the Salesforce account.
This will cause a "portal" button to appear on the Salesforce login screen, enabling SAML SSO.
Note: The "portal" label can be changed under "Identity > Single Sign-On Settings > Single Sign-On Configuration".
Return to the TrustLogin admin page again.
TrustLogin Admin Page Configuration (Continued)
- In "Service Provider Settings", select "Authentication Context Class".
-
Open the "Authentication Context Class" field, and select and configure one option from the list according to the authentication method you use.
Note: "Authentication Context Class" is a setting that indicates the authentication strength (authentication method) required at the time of authentication.
Due to a Salesforce specification change (effective Tuesday, February 3, 2026), an additional "Authentication Context Class" setting is now required.
- Click "Select Metadata" and upload the metadata you downloaded from Salesforce.
- Click the "Register" button to save.
TrustLogin User Configuration
① When a User Adds It from My Page
Note: The administrator must configure the SAML app in advance.
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Salesforce (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for and click the "Salesforce (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.