Newt SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Newt is required.

  • Please refer to the manual provided by Newt for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Newt (SAML)".
    Newt.png

  3. Note down the values of "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring Newt.
Do not click the "Register" button yet — open Newt in a separate window.

Newt Settings

  1. Log in to Newt with an administrator account and select "Space Settings".
    Newt02.png

  2. Open "Security > Single Sign-On". Click the copy button for "Entity ID", "Sign-on URL", and "Sign-out URL" under "Service Provider Configuration Information" and note them down.
    Newt03.png

  3. Configure "Identity Provider Configuration Information" as follows, and click "Save".
    Entity ID The "Issuer / Entity ID" noted down from TrustLogin
    Sign-on URL The "Identity Provider URL" noted down from TrustLogin
    Sign-out URL https://portal.trustlogin.com/
    X.509 Certificate Paste in the contents of the "Certificate" noted down from TrustLogin
    Default Role Select the space role to be assigned to an account when it newly joins the space via SAML JIT.
    Default App to Join Select the App to join when the account newly joins the space via SAML JIT.
    Restricted Mode

    Prohibits members who belong to the space from logging in using an email address and password, Google login, or other SSO methods. If you enable this, we recommend doing so only after confirming that SAML authentication is working successfully.


    Newt04.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Entity ID The "Entity ID" noted down from Newt
    ACS URL to Service The "Sign-on URL" noted down from Newt
    Logout URL

    The "Sign-out URL" noted down from Newt
    Note: Single logout is planned to be added as a feature in the future, but it is not yet implemented and does not currently work


    Newt05.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Newt (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Newt (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

First Login Method

When an existing user logs in via SAML authentication, their user information is linked at the first login.
This step is not required for SAML JIT.

  1. At the first login via SAML authentication, an identity verification email is sent to the corresponding email address.Newt06.png

  2. Check the email and click the link to go to the password login screen. After entering the email address and password, log in by clicking the "Log In" button.
    Note: If the user accesses the link while already logged in to a Newt account with the corresponding email address, the screen below will not appear and entering the email address and password is not required.
    Newt07.png

  3. After logging in to Newt from the single sign-on confirmation screen, the information linkage is complete.
    From the second login onward, no password entry is required and you can log in via SSO.

Newt SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Newt is required.

  • Please refer to the manual provided by Newt for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Newt (SAML)".
    Newt.png

  3. Note down the values of "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring Newt.
Do not click the "Register" button yet — open Newt in a separate window.

Newt Settings

  1. Log in to Newt with an administrator account and select "Space Settings".
    Newt02.png

  2. Open "Security > Single Sign-On". Click the copy button for "Entity ID", "Sign-on URL", and "Sign-out URL" under "Service Provider Configuration Information" and note them down.
    Newt03.png

  3. Configure "Identity Provider Configuration Information" as follows, and click "Save".
    Entity ID The "Issuer / Entity ID" noted down from TrustLogin
    Sign-on URL The "Identity Provider URL" noted down from TrustLogin
    Sign-out URL https://portal.trustlogin.com/
    X.509 Certificate Paste in the contents of the "Certificate" noted down from TrustLogin
    Default Role Select the space role to be assigned to an account when it newly joins the space via SAML JIT.
    Default App to Join Select the App to join when the account newly joins the space via SAML JIT.
    Restricted Mode

    Prohibits members who belong to the space from logging in using an email address and password, Google login, or other SSO methods. If you enable this, we recommend doing so only after confirming that SAML authentication is working successfully.


    Newt04.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Entity ID The "Entity ID" noted down from Newt
    ACS URL to Service The "Sign-on URL" noted down from Newt
    Logout URL

    The "Sign-out URL" noted down from Newt
    Note: Single logout is planned to be added as a feature in the future, but it is not yet implemented and does not currently work


    Newt05.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Newt (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Newt (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

First Login Method

When an existing user logs in via SAML authentication, their user information is linked at the first login.
This step is not required for SAML JIT.

  1. At the first login via SAML authentication, an identity verification email is sent to the corresponding email address.Newt06.png

  2. Check the email and click the link to go to the password login screen. After entering the email address and password, log in by clicking the "Log In" button.
    Note: If the user accesses the link while already logged in to a Newt account with the corresponding email address, the screen below will not appear and entering the email address and password is not required.
    Newt07.png

  3. After logging in to Newt from the single sign-on confirmation screen, the information linkage is complete.
    From the second login onward, no password entry is required and you can log in via SSO.