How to Configure SAML Authentication for Chatwork

Item

Details

Prerequisites

  • Advance setup in Chatwork is required.

  • You must create a Chatwork account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Chatwork.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

Settings on the SP Side

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (account management is possible from TrustLogin)

Supports SAML JIT provisioning (account management is possible from TrustLogin; user deletion is not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Company App Registration" screen and select "Chatwork (SAML)".
    02.png

  3. Note down the values of the "Identity Provider URL" and "Issuer/Entity ID" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to the settings on the Chatwork side.
Without clicking the "Register" button, log in to Chatwork with an administrator account in a separate window.

Chatwork Settings

  1. Select "Administrator Settings" from the drop-down menu at the top right.
    04.png

  2. Select "Login Restrictions" from the menu on the left.
    05.png

  3. Configure each item as follows, then click the "Save" button at the end to save.
    Set up a dedicated login URL

    Check the box and enter any string of your choice in the box below

    Enable single sign-on using SAML authentication Check the box
    Identity Provider's Login URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider's Entity ID The "Issuer/Entity ID" obtained from TrustLogin
    URL to redirect to after logout Configure according to your operational needs
    The public key certificate the Identity Provider uses for signing The contents of the "Certificate" obtained from TrustLogin
    Administrator login URL that does not use SAML authentication If there is an error in the SAML settings, you can log in from here.
    We recommend keeping a record of this URL

    06.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Enter the dedicated login URL string that you set in Chatwork into the blank "Login URL" field.
    07.png

  2. Click the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Chatwork (SAML)" on the "App Registration" screen, then click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for the "Chatwork (SAML)" app and click it.
  2. Click "Add Member", select the user you want to add from the member list, then click the "Register" button to add them.

How to Log In

① Logging In from TrustLogin

Click the icon on My Page or in the browser extension to complete the login.

② Logging In with the Mobile App or Desktop App

  1. Enter only your email address and click the login button.
    mobile.png

  2. You will be redirected to the TrustLogin authentication screen.
  3. Single sign-on will be completed, and you will be logged in to Chatwork.

How to Configure SAML Authentication for Chatwork

Item

Details

Prerequisites

  • Advance setup in Chatwork is required.

  • You must create a Chatwork account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Chatwork.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

Settings on the SP Side

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (account management is possible from TrustLogin)

Supports SAML JIT provisioning (account management is possible from TrustLogin; user deletion is not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Company App Registration" screen and select "Chatwork (SAML)".
    02.png

  3. Note down the values of the "Identity Provider URL" and "Issuer/Entity ID" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to the settings on the Chatwork side.
Without clicking the "Register" button, log in to Chatwork with an administrator account in a separate window.

Chatwork Settings

  1. Select "Administrator Settings" from the drop-down menu at the top right.
    04.png

  2. Select "Login Restrictions" from the menu on the left.
    05.png

  3. Configure each item as follows, then click the "Save" button at the end to save.
    Set up a dedicated login URL

    Check the box and enter any string of your choice in the box below

    Enable single sign-on using SAML authentication Check the box
    Identity Provider's Login URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider's Entity ID The "Issuer/Entity ID" obtained from TrustLogin
    URL to redirect to after logout Configure according to your operational needs
    The public key certificate the Identity Provider uses for signing The contents of the "Certificate" obtained from TrustLogin
    Administrator login URL that does not use SAML authentication If there is an error in the SAML settings, you can log in from here.
    We recommend keeping a record of this URL

    06.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Enter the dedicated login URL string that you set in Chatwork into the blank "Login URL" field.
    07.png

  2. Click the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Chatwork (SAML)" on the "App Registration" screen, then click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for the "Chatwork (SAML)" app and click it.
  2. Click "Add Member", select the user you want to add from the member list, then click the "Register" button to add them.

How to Log In

① Logging In from TrustLogin

Click the icon on My Page or in the browser extension to complete the login.

② Logging In with the Mobile App or Desktop App

  1. Enter only your email address and click the login button.
    mobile.png

  2. You will be redirected to the TrustLogin authentication screen.
  3. Single sign-on will be completed, and you will be logged in to Chatwork.