How to Configure SAML Authentication for Bill One

Item

Details

Pre-check

  • Advance configuration in Bill One is required.

  • You must create a Bill One account using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Bill One.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Bill One (SAML)."
    Bill One.png

  3. Make a note of the values for "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

  4. Convert the extension of the downloaded certificate to ".cer."

Now, switch to the Bill One settings.
Do not click the "Register" button yet; open Bill One in a separate window.

Bill One Settings

  1. From the Bill One global menu, click "System Settings."
    20241001-bill-one-sso-setting-1.png

  2. From the side menu, click "SSO (Single Sign-On) Settings."
    20241001-bill-one-sso-setting-2.png

  3. In "Step 1," register your domain and verify domain ownership. For detailed configuration steps, please refer to the manual provided by Bill One.
    Bill One's manual is available here

  4. Configure "Step 2. Integration Settings" as follows.
    Integration Method SAML
    IdP Identifier The "Issuer/Entity ID" you noted down from TrustLogin
    Sign-in URL The "IdP URL" you noted down from TrustLogin
    SAML Signing Certificate The "certificate" you noted down from TrustLogin, with its extension converted to ".cer"

    20240925_bill_one_sso_setting.png

  5. Using the copy buttons, make a note of the "Response URL (AssertionConsumerURL)," "Identifier (EntityID)," and "URL for SSO." Configure the "Certificate Renewal Reminder" as needed.
    20240925_bill_one_sso_setting02.png

Now, return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "URL for SSO" you noted down from Bill One
    Entity ID The "Identifier (EntityID)" you noted down from Bill One
    ACS URL to the Service The "Response URL (AssertionConsumerURL)" you noted down from Bill One

    Bill One01.png

  2. Save by clicking the "Register" button.

  3. Add the user who is currently performing the SAML configuration to the "Bill One (SAML)" app.
    From "Admin Page > App," search for the "Bill One (SAML)" app, and add the user via "Add Member."

Bill One Settings (Continued)

  1. Click the "Start Connection Test" button and confirm that authentication succeeds.
    20241001-bill-one-sso-setting-3.png

  2. If the connection test completes without issues, the test is finished. Click [Save Settings and Proceed] to save the configuration.
    20241001-bill-one-sso-setting-4.png

  3. Change the status of users who will use SSO to [In Use].

  4. If you want to enable SSO in bulk for each domain, click [Bulk Change], select the domains for which you want to enable SSO from the domain list displayed on the bulk change screen, and click [Change to In Use].
    For details, please refer to the Bill One manual.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Bill One (SAML)," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Bill One (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Bill One

Item

Details

Pre-check

  • Advance configuration in Bill One is required.

  • You must create a Bill One account using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Bill One.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Bill One (SAML)."
    Bill One.png

  3. Make a note of the values for "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

  4. Convert the extension of the downloaded certificate to ".cer."

Now, switch to the Bill One settings.
Do not click the "Register" button yet; open Bill One in a separate window.

Bill One Settings

  1. From the Bill One global menu, click "System Settings."
    20241001-bill-one-sso-setting-1.png

  2. From the side menu, click "SSO (Single Sign-On) Settings."
    20241001-bill-one-sso-setting-2.png

  3. In "Step 1," register your domain and verify domain ownership. For detailed configuration steps, please refer to the manual provided by Bill One.
    Bill One's manual is available here

  4. Configure "Step 2. Integration Settings" as follows.
    Integration Method SAML
    IdP Identifier The "Issuer/Entity ID" you noted down from TrustLogin
    Sign-in URL The "IdP URL" you noted down from TrustLogin
    SAML Signing Certificate The "certificate" you noted down from TrustLogin, with its extension converted to ".cer"

    20240925_bill_one_sso_setting.png

  5. Using the copy buttons, make a note of the "Response URL (AssertionConsumerURL)," "Identifier (EntityID)," and "URL for SSO." Configure the "Certificate Renewal Reminder" as needed.
    20240925_bill_one_sso_setting02.png

Now, return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "URL for SSO" you noted down from Bill One
    Entity ID The "Identifier (EntityID)" you noted down from Bill One
    ACS URL to the Service The "Response URL (AssertionConsumerURL)" you noted down from Bill One

    Bill One01.png

  2. Save by clicking the "Register" button.

  3. Add the user who is currently performing the SAML configuration to the "Bill One (SAML)" app.
    From "Admin Page > App," search for the "Bill One (SAML)" app, and add the user via "Add Member."

Bill One Settings (Continued)

  1. Click the "Start Connection Test" button and confirm that authentication succeeds.
    20241001-bill-one-sso-setting-3.png

  2. If the connection test completes without issues, the test is finished. Click [Save Settings and Proceed] to save the configuration.
    20241001-bill-one-sso-setting-4.png

  3. Change the status of users who will use SSO to [In Use].

  4. If you want to enable SSO in bulk for each domain, click [Bulk Change], select the domains for which you want to enable SSO from the domain list displayed on the bulk change screen, and click [Change to In Use].
    For details, please refer to the Bill One manual.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Bill One (SAML)," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Bill One (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.