How to Configure SAML Authentication for Ekispert Commuting Expenses Web

Item

Details

Pre-check

  • Prior configuration in Ekispert Commuting Expenses Web is required.

  • You need to register the same email address as TrustLogin for the SSO-ID in Ekispert Commuting Expenses Web.

  • For the latest setup instructions, please check the manual provided by Ekispert Commuting Expenses Web.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Preparation

●TrustLogin Configuration

You need to configure a custom attribute in advance to link the company ID of Ekispert Commuting Expenses Web to the member information in TrustLogin. Set the company ID of Ekispert Commuting Expenses Web as the attribute value.

[TrustLogin Custom Attribute Configuration Example]
通勤費Web01.png
Please refer to the following pages for configuration instructions.

●Ekispert Commuting Expenses Web Configuration

Select an employee from "Master Management > Employee Information" and enter the same
email address as TrustLogin in the "SSO-ID" field.

通勤費Web02.png


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Register the "Application Name" and "Icon" (optional).
    通勤費Web03.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information". Also, download the certificate using the "Get Certificate" button.003.png

  4. Configure the "Service Provider Settings" as follows.
    Name ID Value Select "Member" - "email" (default setting)
    Entity ID TsukinhiWeb
    Name ID Format unspecified
    ACS URL for the Service https://teiki.ekispert.com/teiki/Saml2/Acs

    通勤費Web04.png

  5. Add a row (attribute) using the "Add SAML Attribute" button under "SAML Attribute Settings" and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    tenantid Unspecified tenantid

    Custom attribute

    The attribute name you configured


    通勤費Web05.png

  6. Save by clicking the "Register" button.

  7. Send the TrustLogin metadata and certificate to your contact at Val Laboratory Corporation and request SAML configuration.

  8. Once you receive notification from your contact at Val Laboratory Corporation that the metadata configuration is complete, add the app and try SAML authentication.


Ekispert Commuting Expenses Web Configuration

  1. Select an employee from "Master Management > Employee Information". For "Password Login," select either "Not allowed (SSO only)" or "Allowed," and update the information.
    Note: If you select "Not allowed (SSO only)," users will no longer be able to set a new password or reset their password. This setting also changes the login URL included in notification emails.
    (SSO only → URL for SSO login; Password allowed → URL for password login)
    通勤費Web06.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Ekispert Commuting Expenses Web

Item

Details

Pre-check

  • Prior configuration in Ekispert Commuting Expenses Web is required.

  • You need to register the same email address as TrustLogin for the SSO-ID in Ekispert Commuting Expenses Web.

  • For the latest setup instructions, please check the manual provided by Ekispert Commuting Expenses Web.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Preparation

●TrustLogin Configuration

You need to configure a custom attribute in advance to link the company ID of Ekispert Commuting Expenses Web to the member information in TrustLogin. Set the company ID of Ekispert Commuting Expenses Web as the attribute value.

[TrustLogin Custom Attribute Configuration Example]
通勤費Web01.png
Please refer to the following pages for configuration instructions.

●Ekispert Commuting Expenses Web Configuration

Select an employee from "Master Management > Employee Information" and enter the same
email address as TrustLogin in the "SSO-ID" field.

通勤費Web02.png


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Register the "Application Name" and "Icon" (optional).
    通勤費Web03.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information". Also, download the certificate using the "Get Certificate" button.003.png

  4. Configure the "Service Provider Settings" as follows.
    Name ID Value Select "Member" - "email" (default setting)
    Entity ID TsukinhiWeb
    Name ID Format unspecified
    ACS URL for the Service https://teiki.ekispert.com/teiki/Saml2/Acs

    通勤費Web04.png

  5. Add a row (attribute) using the "Add SAML Attribute" button under "SAML Attribute Settings" and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    tenantid Unspecified tenantid

    Custom attribute

    The attribute name you configured


    通勤費Web05.png

  6. Save by clicking the "Register" button.

  7. Send the TrustLogin metadata and certificate to your contact at Val Laboratory Corporation and request SAML configuration.

  8. Once you receive notification from your contact at Val Laboratory Corporation that the metadata configuration is complete, add the app and try SAML authentication.


Ekispert Commuting Expenses Web Configuration

  1. Select an employee from "Master Management > Employee Information". For "Password Login," select either "Not allowed (SSO only)" or "Allowed," and update the information.
    Note: If you select "Not allowed (SSO only)," users will no longer be able to set a new password or reset their password. This setting also changes the login URL included in notification emails.
    (SSO only → URL for SSO login; Password allowed → URL for password login)
    通勤費Web06.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.