|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
|
Email address |
| 〇 |
Custom attribute Note: For how to configure custom attributes, see here |
|
|
SP-side Configuration |
|
Configured by the administrator |
| 〇 |
Request configuration from the SP |
|
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
|
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
※ |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
※ |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Enabled only for users with SAML authentication applied on the SP |
|
|
Notes |
|
|
|
Table of Contents: |
Prerequisites
Add a Custom Attribute to User Information
Add hakaru.ai's "Login ID" information to the TrustLogin member information using a custom attribute.
[hakaru.ai Account Information Screen]
[TrustLogin Custom Attribute Configuration Example]
The attribute name for the custom attribute is arbitrary
Please refer to the following pages for instructions on how to configure custom attributes.
Custom Attribute Setup (Individual Registration)
Custom Attribute Setup (Bulk Registration)
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Company App" screen, search and select "hakaru.ai (SAML)".
- Download the metadata using the "Download Metadata" button under "Identity Provider Information".
- Save by clicking the "Register" button.
- Send the downloaded metadata to a representative at GMO GlobalSign Holdings, Inc. You will also receive hakaru.ai's SAML configuration information to be configured on the TrustLogin side.
- Once you receive notification of completed configuration from GMO GlobalSign Holdings, Inc., open "Change SAML App Settings" for the "hakaru.ai (SAML)" app on the TrustLogin app management screen.
- Configure "Service Provider Settings" as follows.
Entity ID hakaru.ai's "Entity ID" Value for Name ID Custom attribute - the attribute name you configured ACS URL to Service hakaru.ai's "Single Sign-On URL"
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "hakaru.ai (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Save" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for and click the "hakaru.ai (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.
hakaru.ai User Settings
- Log in to hakaru.ai, click your username in the top right, and open "Personal Settings". Scroll down to "Single Sign-On" and click "Authenticate".
- If you are not logged in to TrustLogin, you will be redirected to TrustLogin, so please log in.
When "Single sign-on authentication succeeded" is displayed, the SSO linkage is complete.
Note: This operation must be performed by the user who wants to log in via SSO.
Administrators cannot perform the SSO linkage on behalf of a user.
Login Method
When logging in for the first time after enabling SSO, or when performing SSO in a browser you are accessing for the first time, you must log in with your password the first time.
In a browser where you have logged in via SSO once, the "Sign in with SSO" button will be displayed for subsequent logins. Please log in using "Sign in with SSO".