How to Configure SAML Authentication for freee

Item Details
Pre-Check
  • Prior configuration in the freee Account Management screen is required.
  • You must create an account in the freee Account Management screen using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by freee.
Name ID Email address
Custom attribute Note: For instructions on how to configure a custom attribute, click here
SP-side Configuration Configured by the administrator
Request configuration from the SP
Provisioning Provisioning via API supported (account management possible in TrustLogin)
SAML JITprovisioning supported (account management possible in TrustLogin; user deletion not supported)
None (accounts are created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:
Enabled only for users to whom SAML authentication has been applied on the SP
Notes

By completing the setup in this manual, you can establish SSO connections with the following services.

・freee Accounting (*)
・freee HR & Payroll (*)
・freee Invoice (*)
・freee Sales Management
・freee Project Management
・freee Tax Return (*)

(*) Both the web and mobile app versions are covered. Note that freee Accounting also covers the expense reimbursement app, in addition to the mobile app.

SAML login is not enforced for the following services even when SAML is enabled.
・freee Received Invoices
・freee Sign

Table of Contents:

TrustLogin Admin Page Settings

freee Settings

TrustLogin Admin Page Settings (Continued)

freee Settings (Continued)

TrustLogin Admin Page Settings (Optional)

TrustLogin User Settings

Native App Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. Search on the "Register Company App" screen and select "freee (SAML)".
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png


Now, switch to configuring freee.
Do not click the "Register" button — open the freee Account Management screen in a separate window.

freee Settings

  1. Open "Business Management > Security" in the freee Account Management screen, and click "Set Up SAML SSO".


  2. Copy the "Entity ID" and "ACS URL" using the copy buttons on the right, then click "Upload Metadata" to upload the metadata obtained from TrustLogin.
    Finally, click "Save" to save the settings.


    Return to the TrustLogin Admin Page again.
    Keep the freee Account Management screen page open as is.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Entity ID The "Entity ID" you copied from freee
    ACS URL for the Service The "ACS URL" you copied from freee


  2. Save by clicking the "Register" button.
  3. To perform the connection test in the freee settings that follow, add the administrator configuring these settings as a member of the SAML app you created.
    In the "Admin Page > App" menu, search for the "freee (SAML)" app and use "Add Member" to add the administrator account.

Return to the freee Account Management screen again.

freee Settings (Continued)

  1. Click "Connection Test (navigate to external site)" at the bottom of the page to run the connection test.

  2. If the connection test succeeds, the message "Connection test succeeded." will be displayed.
    Click "Enable" to activate the SAML connection.

  3. Open "Business Management > Members" in the freee Account Management screen, and click "Bulk Operations > Bulk Enable SAML SSO".

  4. Select the members for whom you want to enable SAML SSO, and click "Enable".

  5. A notice will be displayed. If you have no concerns about the notice, click "Enable".

  6. SAML SSO is now enabled, and members can log in using SAML.


TrustLogin Admin Page Settings (Optional)

  1. By configuring "Service Provider Settings" as follows, you can specify which product is displayed after logging in from TrustLogin.
Transfer URL After Successful SP Authentication

By setting the following values, you can specify which product is displayed after logging in from TrustLogin.

Value for Transfer URL After Successful SP Authentication Product Displayed After Login
accounting freee Accounting
payroll freee HR & Payroll
project_management freee Project Management
sales_management freee Sales Management
invoice freee Invoice
(If not specified) Account Management screen

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "freee (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "freee (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Native App Login Method

  1. Open the native app and tap "Log In".

  2. When the message shown in the image below appears, tap "Continue".

  3. Enter your TrustLogin email address and tap "Log In".

How to Configure SAML Authentication for freee

Item Details
Pre-Check
  • Prior configuration in the freee Account Management screen is required.
  • You must create an account in the freee Account Management screen using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by freee.
Name ID Email address
Custom attribute Note: For instructions on how to configure a custom attribute, click here
SP-side Configuration Configured by the administrator
Request configuration from the SP
Provisioning Provisioning via API supported (account management possible in TrustLogin)
SAML JITprovisioning supported (account management possible in TrustLogin; user deletion not supported)
None (accounts are created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:
Enabled only for users to whom SAML authentication has been applied on the SP
Notes

By completing the setup in this manual, you can establish SSO connections with the following services.

・freee Accounting (*)
・freee HR & Payroll (*)
・freee Invoice (*)
・freee Sales Management
・freee Project Management
・freee Tax Return (*)

(*) Both the web and mobile app versions are covered. Note that freee Accounting also covers the expense reimbursement app, in addition to the mobile app.

SAML login is not enforced for the following services even when SAML is enabled.
・freee Received Invoices
・freee Sign

Table of Contents:

TrustLogin Admin Page Settings

freee Settings

TrustLogin Admin Page Settings (Continued)

freee Settings (Continued)

TrustLogin Admin Page Settings (Optional)

TrustLogin User Settings

Native App Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. Search on the "Register Company App" screen and select "freee (SAML)".
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png


Now, switch to configuring freee.
Do not click the "Register" button — open the freee Account Management screen in a separate window.

freee Settings

  1. Open "Business Management > Security" in the freee Account Management screen, and click "Set Up SAML SSO".


  2. Copy the "Entity ID" and "ACS URL" using the copy buttons on the right, then click "Upload Metadata" to upload the metadata obtained from TrustLogin.
    Finally, click "Save" to save the settings.


    Return to the TrustLogin Admin Page again.
    Keep the freee Account Management screen page open as is.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Entity ID The "Entity ID" you copied from freee
    ACS URL for the Service The "ACS URL" you copied from freee


  2. Save by clicking the "Register" button.
  3. To perform the connection test in the freee settings that follow, add the administrator configuring these settings as a member of the SAML app you created.
    In the "Admin Page > App" menu, search for the "freee (SAML)" app and use "Add Member" to add the administrator account.

Return to the freee Account Management screen again.

freee Settings (Continued)

  1. Click "Connection Test (navigate to external site)" at the bottom of the page to run the connection test.

  2. If the connection test succeeds, the message "Connection test succeeded." will be displayed.
    Click "Enable" to activate the SAML connection.

  3. Open "Business Management > Members" in the freee Account Management screen, and click "Bulk Operations > Bulk Enable SAML SSO".

  4. Select the members for whom you want to enable SAML SSO, and click "Enable".

  5. A notice will be displayed. If you have no concerns about the notice, click "Enable".

  6. SAML SSO is now enabled, and members can log in using SAML.


TrustLogin Admin Page Settings (Optional)

  1. By configuring "Service Provider Settings" as follows, you can specify which product is displayed after logging in from TrustLogin.
Transfer URL After Successful SP Authentication

By setting the following values, you can specify which product is displayed after logging in from TrustLogin.

Value for Transfer URL After Successful SP Authentication Product Displayed After Login
accounting freee Accounting
payroll freee HR & Payroll
project_management freee Project Management
sales_management freee Sales Management
invoice freee Invoice
(If not specified) Account Management screen

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "freee (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "freee (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Native App Login Method

  1. Open the native app and tap "Log In".

  2. When the message shown in the image below appears, tap "Continue".

  3. Enter your TrustLogin email address and tap "Log In".