Contentful SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Contentful is required.

  • The user's first and last name are synced only at the time of new registration.

  • Please refer to the manual provided by Contentful for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Contentful (SAML)".
    02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring Contentful.
Do not click the "Register" button yet — open Contentful in a separate window.

Contentful Settings

  1. Open the organization settings page (Organization settings) and open "Access tools > Single Sign-On (SSO)".
    04.png

  2. Set any name you like for "Single sign-on (SSO) name". Click the copy button to the right of "Audience URI" and "Assertion Consumer Service (ACS) URL" and note down each value.
    05.png

  3. Configure each item under "Test your connection" as follows.
    Identity Provider Select "Other"
    SSO Redirect URL The "Identity Provider URL" obtained from TrustLogin
    X.509 Certificate The contents of the "Certificate" obtained from TrustLogin

    06.png

Now return to the TrustLogin Admin Page again.
Leave the Contentful page open as is.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Audience URI" obtained from Contentful
    ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Contentful

    08.png

  2. Save by clicking the "Register" button.

  3. Since you will perform a connection test in Contentful next, add the account of the administrator who is configuring the settings to the SAML app you created.
    For instructions on how to add a member, see "TrustLogin User Settings".

Now return to the Contentful settings page again.

Contentful Settings (Continued)

  1. Click the "Test connection" button under "Test your connection".
    07.png

    If "Connection test successful!" is displayed, the connection test has succeeded.
    09.png

  2. Click "Activate SSO" in the upper right to enable single sign-on.
    10.png

  3. If you want to restrict the user login method to SSO only, turn on "Require users to sign in with SSO" under "Set login restrictions". Note that turning this on will disable password login.
    11.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Contentful (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Contentful (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

SP-Initiated Login Method

  1. Open the Contentful login page and click "Log in via SSO".
    14.png

  2. Enter the SSO name you configured in step 2 of "Contentful Settings" and click the "Continue" button.
    15.png

  3. If you are already logged in to TrustLogin, you will be logged in to Contentful immediately.
    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen; once you authenticate, login to Contentful will be complete.

About the First Login

① When a User Already Added to the Organization Logs In

  1. At first login via SSO, the following screen is displayed and a verification email is sent to the email address.
    12.png

  2. Click the button in the email you receive to complete verification, after which you will be able to log in.

When a New User Logs In

  1. When you log in via SSO, a user registration screen is displayed. The last name, first name, and email address are automatically populated with information from TrustLogin. Configure the other fields and click the Join button to join the organization.
    13.png

  2. Login is now complete. Note, however, that while the user is added as an organization user, space and team settings must be configured separately by an administrator.

Contentful SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Contentful is required.

  • The user's first and last name are synced only at the time of new registration.

  • Please refer to the manual provided by Contentful for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Contentful (SAML)".
    02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring Contentful.
Do not click the "Register" button yet — open Contentful in a separate window.

Contentful Settings

  1. Open the organization settings page (Organization settings) and open "Access tools > Single Sign-On (SSO)".
    04.png

  2. Set any name you like for "Single sign-on (SSO) name". Click the copy button to the right of "Audience URI" and "Assertion Consumer Service (ACS) URL" and note down each value.
    05.png

  3. Configure each item under "Test your connection" as follows.
    Identity Provider Select "Other"
    SSO Redirect URL The "Identity Provider URL" obtained from TrustLogin
    X.509 Certificate The contents of the "Certificate" obtained from TrustLogin

    06.png

Now return to the TrustLogin Admin Page again.
Leave the Contentful page open as is.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Audience URI" obtained from Contentful
    ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Contentful

    08.png

  2. Save by clicking the "Register" button.

  3. Since you will perform a connection test in Contentful next, add the account of the administrator who is configuring the settings to the SAML app you created.
    For instructions on how to add a member, see "TrustLogin User Settings".

Now return to the Contentful settings page again.

Contentful Settings (Continued)

  1. Click the "Test connection" button under "Test your connection".
    07.png

    If "Connection test successful!" is displayed, the connection test has succeeded.
    09.png

  2. Click "Activate SSO" in the upper right to enable single sign-on.
    10.png

  3. If you want to restrict the user login method to SSO only, turn on "Require users to sign in with SSO" under "Set login restrictions". Note that turning this on will disable password login.
    11.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Contentful (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Contentful (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

SP-Initiated Login Method

  1. Open the Contentful login page and click "Log in via SSO".
    14.png

  2. Enter the SSO name you configured in step 2 of "Contentful Settings" and click the "Continue" button.
    15.png

  3. If you are already logged in to TrustLogin, you will be logged in to Contentful immediately.
    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen; once you authenticate, login to Contentful will be complete.

About the First Login

① When a User Already Added to the Organization Logs In

  1. At first login via SSO, the following screen is displayed and a verification email is sent to the email address.
    12.png

  2. Click the button in the email you receive to complete verification, after which you will be able to log in.

When a New User Logs In

  1. When you log in via SSO, a user registration screen is displayed. The last name, first name, and email address are automatically populated with information from TrustLogin. Configure the other fields and click the Join button to join the organization.
    13.png

  2. Login is now complete. Note, however, that while the user is added as an organization user, space and team settings must be configured separately by an administrator.