toitta SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in toitta is required.

  • For the latest setup instructions, please check the manual provided by toitta.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:

Notes

  • Once your application for the SAML feature is complete, toitta will issue a temporary URL for the SAML setup page. Note: This URL is valid for one week from the date of issuance, so please be aware of this.
  • Synchronization of the user's last name and first name via SAML JIT only occurs when a new user is created. It is not synchronized on subsequent logins.
  • Users who were already using a Google or Microsoft account can continue to log in as the same user after SAML is enabled, provided their email address matches their TrustLogin email address. If the email addresses do not match, they will be registered as a new, separate user. Note: After SAML is enabled, users will no longer be able to log in with their Google or Microsoft account.

Table of Contents:

TrustLogin Admin Page Settings

toitta Settings

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "toitta (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

  4. In "Service Provider Settings" > "Login URL", enter your toitta "Organization ID".
    04.png

  5. Click the "Register" button to save your settings.

toitta Settings

  1. Open the SAML setup page issued by toitta and select "Generic SAML 2.0".
    06.png

  2. Click the "Next Step" button to continue.
    08.png

  3. Click the "Next Step" button to continue.
    09.png

  4. Paste the entire contents of the "metadata" obtained from TrustLogin into "Raw IdP XML", then click the "Save" button to save.
    10.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "toitta (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the "toitta (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

  1. From the TrustLogin My Page, click "toitta (SAML)", or open https://<your toitta Organization ID>.toitta.com/login and click the "Sign In" button.
    12.png

    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin login screen. Log in there.

  2. Select a team to get started.

toitta SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in toitta is required.

  • For the latest setup instructions, please check the manual provided by toitta.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:

Notes

  • Once your application for the SAML feature is complete, toitta will issue a temporary URL for the SAML setup page. Note: This URL is valid for one week from the date of issuance, so please be aware of this.
  • Synchronization of the user's last name and first name via SAML JIT only occurs when a new user is created. It is not synchronized on subsequent logins.
  • Users who were already using a Google or Microsoft account can continue to log in as the same user after SAML is enabled, provided their email address matches their TrustLogin email address. If the email addresses do not match, they will be registered as a new, separate user. Note: After SAML is enabled, users will no longer be able to log in with their Google or Microsoft account.

Table of Contents:

TrustLogin Admin Page Settings

toitta Settings

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "toitta (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

  4. In "Service Provider Settings" > "Login URL", enter your toitta "Organization ID".
    04.png

  5. Click the "Register" button to save your settings.

toitta Settings

  1. Open the SAML setup page issued by toitta and select "Generic SAML 2.0".
    06.png

  2. Click the "Next Step" button to continue.
    08.png

  3. Click the "Next Step" button to continue.
    09.png

  4. Paste the entire contents of the "metadata" obtained from TrustLogin into "Raw IdP XML", then click the "Save" button to save.
    10.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "toitta (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the "toitta (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

  1. From the TrustLogin My Page, click "toitta (SAML)", or open https://<your toitta Organization ID>.toitta.com/login and click the "Sign In" button.
    12.png

    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin login screen. Log in there.

  2. Select a team to get started.