How to Configure SAML Authentication for hakaru.ai

 Item

Details 

Prior Confirmation

  • Prior configuration in hakaru.ai is required.

  • You need to register hakaru.ai's "Login ID" as a TrustLogin custom attribute in advance.

  • For the latest setup instructions, please refer to the manual provided by hakaru.ai.

Name ID

 

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

 

Configured by the administrator

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Enabled only for users with SAML authentication applied on the SP

Notes

  • When logging in for the first time after enabling SSO, or when performing SSO in a browser you are accessing for the first time, you must log in with your password the first time.From the second time onward, you can log in via SSO using the "Sign in with SSO" button.
  • In the TrustLogin Mobile App's in-app browser, if you log out of TrustLogin, you will need to log in with your password again.

 

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

TrustLogin User Settings

hakaru.ai User Settings

Login Method


Prerequisites

Add a Custom Attribute to User Information

Add hakaru.ai's "Login ID" information to the TrustLogin member information using a custom attribute.

[hakaru.ai Account Information Screen]
hakaru.ai.png

[TrustLogin Custom Attribute Configuration Example]

The attribute name for the custom attribute is arbitrary
hakaru.ai01.png

Please refer to the following pages for instructions on how to configure custom attributes.

  Custom Attribute Setup (Individual Registration)

  Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "hakaru.ai (SAML)".
    hakaru.ai04.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

  4. Save by clicking the "Register" button.
  5. Send the downloaded metadata to a representative at GMO GlobalSign Holdings, Inc. You will also receive hakaru.ai's SAML configuration information to be configured on the TrustLogin side.

  6. Once you receive notification of completed configuration from GMO GlobalSign Holdings, Inc., open "Change SAML App Settings" for the "hakaru.ai (SAML)" app on the TrustLogin app management screen.
    hakaru.ai05.png

  7. Configure "Service Provider Settings" as follows.
    Entity ID hakaru.ai's "Entity ID"
    Value for Name ID Custom attribute - the attribute name you configured
    ACS URL to Service hakaru.ai's "Single Sign-On URL"

    hakaru.ai06.png

  8. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "hakaru.ai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "hakaru.ai (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

hakaru.ai User Settings

  1. Log in to hakaru.ai, click your username in the top right, and open "Personal Settings". Scroll down to "Single Sign-On" and click "Authenticate".
    hakaru.ai02.png

  2. If you are not logged in to TrustLogin, you will be redirected to TrustLogin, so please log in.
    When "Single sign-on authentication succeeded" is displayed, the SSO linkage is complete.
    hakaru.ai03.png
    Note: This operation must be performed by the user who wants to log in via SSO.
     Administrators cannot perform the SSO linkage on behalf of a user.


Login Method

When logging in for the first time after enabling SSO, or when performing SSO in a browser you are accessing for the first time, you must log in with your password the first time.

In a browser where you have logged in via SSO once, the "Sign in with SSO" button will be displayed for subsequent logins. Please log in using "Sign in with SSO".
hakaru.ai07.png

 

How to Configure SAML Authentication for hakaru.ai

 Item

Details 

Prior Confirmation

  • Prior configuration in hakaru.ai is required.

  • You need to register hakaru.ai's "Login ID" as a TrustLogin custom attribute in advance.

  • For the latest setup instructions, please refer to the manual provided by hakaru.ai.

Name ID

 

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

 

Configured by the administrator

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Enabled only for users with SAML authentication applied on the SP

Notes

  • When logging in for the first time after enabling SSO, or when performing SSO in a browser you are accessing for the first time, you must log in with your password the first time.From the second time onward, you can log in via SSO using the "Sign in with SSO" button.
  • In the TrustLogin Mobile App's in-app browser, if you log out of TrustLogin, you will need to log in with your password again.

 

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

TrustLogin User Settings

hakaru.ai User Settings

Login Method


Prerequisites

Add a Custom Attribute to User Information

Add hakaru.ai's "Login ID" information to the TrustLogin member information using a custom attribute.

[hakaru.ai Account Information Screen]
hakaru.ai.png

[TrustLogin Custom Attribute Configuration Example]

The attribute name for the custom attribute is arbitrary
hakaru.ai01.png

Please refer to the following pages for instructions on how to configure custom attributes.

  Custom Attribute Setup (Individual Registration)

  Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "hakaru.ai (SAML)".
    hakaru.ai04.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

  4. Save by clicking the "Register" button.
  5. Send the downloaded metadata to a representative at GMO GlobalSign Holdings, Inc. You will also receive hakaru.ai's SAML configuration information to be configured on the TrustLogin side.

  6. Once you receive notification of completed configuration from GMO GlobalSign Holdings, Inc., open "Change SAML App Settings" for the "hakaru.ai (SAML)" app on the TrustLogin app management screen.
    hakaru.ai05.png

  7. Configure "Service Provider Settings" as follows.
    Entity ID hakaru.ai's "Entity ID"
    Value for Name ID Custom attribute - the attribute name you configured
    ACS URL to Service hakaru.ai's "Single Sign-On URL"

    hakaru.ai06.png

  8. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "hakaru.ai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "hakaru.ai (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

hakaru.ai User Settings

  1. Log in to hakaru.ai, click your username in the top right, and open "Personal Settings". Scroll down to "Single Sign-On" and click "Authenticate".
    hakaru.ai02.png

  2. If you are not logged in to TrustLogin, you will be redirected to TrustLogin, so please log in.
    When "Single sign-on authentication succeeded" is displayed, the SSO linkage is complete.
    hakaru.ai03.png
    Note: This operation must be performed by the user who wants to log in via SSO.
     Administrators cannot perform the SSO linkage on behalf of a user.


Login Method

When logging in for the first time after enabling SSO, or when performing SSO in a browser you are accessing for the first time, you must log in with your password the first time.

In a browser where you have logged in via SSO once, the "Sign in with SSO" button will be displayed for subsequent logins. Please log in using "Sign in with SSO".
hakaru.ai07.png