Synergy! SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Synergy! is required.

  • For the latest setup instructions, please check the manual provided by Synergy!.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for SSO users

Notes

  • SSO users can only be newly created via SAML JIT, and are distinct from password users that administrators additionally register in the user management screen.

Table of Contents:

Prerequisites

TrustLogin Admin Page Configuration

Synergy! Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration

Prerequisites

Note: Configure this section only if you want to link and manage the "User Name" and "Permission Group" in Synergy!'s user information using custom attributes from TrustLogin member information.
If you are not linking these, no configuration is required. Please proceed to the next step.


① "User Name"
If you do not configure linkage via a custom attribute, the TrustLogin email address will be set as the user name. You can also specify an existing custom attribute or a member information field such as "Last Name" or "Email Address".

② "Permission Group"
If you do not configure linkage via a custom attribute, the "Default Permission Group" configured in Synergy! will be assigned when the user is created. Changes to the permission group are made by the administrator in Synergy! .


Add a Custom Attribute to User Information

Add the Synergy! "Member ID" information as a custom attribute in TrustLogin member information. The attribute name for the custom attribute can be anything you choose.

[TrustLogin Custom Attribute Configuration Example]
00.png

Please refer to the following pages for instructions on how to configure custom attributes.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

At this point, switch over to configuring the Synergy! side.
Do not click the "Register" button yet — open Synergy! in a separate window.

Synergy! Configuration

  1. Open "Other > Common Settings > SSO Management" and click "Create New".
    04.png

  2. Enter any name (e.g., TrustLogin) for "SSO Configuration Name" and click "Create".
    05.png

  3. Configure each item as follows, and finally save by clicking "Save Settings".
    Entity ID Make a note of the value using the "Copy" button
    ACS URL Make a note of the value using the "Copy" button
    Default Permission Group Specify the permission group to be assigned by default when a new user is created
    (if linkage is configured, the linkage settings take priority)
    SAML 2.0 Metadata The contents of the metadata obtained from TrustLogin
    Enable SSO Configuration ON

    06.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Value for Name ID Member - email
    Entity ID The "Entity ID" obtained from Synergy!
    ACS URL to Service The "ACS URL" obtained from Synergy!

    2025-09-26_11-12-46.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Note: "email" does not need to be configured if "Value for Name ID" is set to "Member - Email Address". If you use something other than the email address for the Name ID, configure it as shown in the table below.
    Note: "displayName" and "authorityGroupId" only need to be configured if you are setting up linkage.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    email Unspecified email

    Member

    Email Address

    displayName Unspecified displayName

    Custom Attribute (*)

    Select the custom attribute configured in Prerequisites (*)

    authorityGroupId Unspecified authorityGroupId

    Custom Attribute

    Select the custom attribute configured in Prerequisites

    (*) You can also select existing TrustLogin member information (such as email address or last name).

    08.png

  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

Note: The SAML app must be configured in advance by an administrator.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Synergy! SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Synergy! is required.

  • For the latest setup instructions, please check the manual provided by Synergy!.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for SSO users

Notes

  • SSO users can only be newly created via SAML JIT, and are distinct from password users that administrators additionally register in the user management screen.

Table of Contents:

Prerequisites

TrustLogin Admin Page Configuration

Synergy! Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration

Prerequisites

Note: Configure this section only if you want to link and manage the "User Name" and "Permission Group" in Synergy!'s user information using custom attributes from TrustLogin member information.
If you are not linking these, no configuration is required. Please proceed to the next step.


① "User Name"
If you do not configure linkage via a custom attribute, the TrustLogin email address will be set as the user name. You can also specify an existing custom attribute or a member information field such as "Last Name" or "Email Address".

② "Permission Group"
If you do not configure linkage via a custom attribute, the "Default Permission Group" configured in Synergy! will be assigned when the user is created. Changes to the permission group are made by the administrator in Synergy! .


Add a Custom Attribute to User Information

Add the Synergy! "Member ID" information as a custom attribute in TrustLogin member information. The attribute name for the custom attribute can be anything you choose.

[TrustLogin Custom Attribute Configuration Example]
00.png

Please refer to the following pages for instructions on how to configure custom attributes.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

At this point, switch over to configuring the Synergy! side.
Do not click the "Register" button yet — open Synergy! in a separate window.

Synergy! Configuration

  1. Open "Other > Common Settings > SSO Management" and click "Create New".
    04.png

  2. Enter any name (e.g., TrustLogin) for "SSO Configuration Name" and click "Create".
    05.png

  3. Configure each item as follows, and finally save by clicking "Save Settings".
    Entity ID Make a note of the value using the "Copy" button
    ACS URL Make a note of the value using the "Copy" button
    Default Permission Group Specify the permission group to be assigned by default when a new user is created
    (if linkage is configured, the linkage settings take priority)
    SAML 2.0 Metadata The contents of the metadata obtained from TrustLogin
    Enable SSO Configuration ON

    06.png

Return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Value for Name ID Member - email
    Entity ID The "Entity ID" obtained from Synergy!
    ACS URL to Service The "ACS URL" obtained from Synergy!

    2025-09-26_11-12-46.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Note: "email" does not need to be configured if "Value for Name ID" is set to "Member - Email Address". If you use something other than the email address for the Name ID, configure it as shown in the table below.
    Note: "displayName" and "authorityGroupId" only need to be configured if you are setting up linkage.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    email Unspecified email

    Member

    Email Address

    displayName Unspecified displayName

    Custom Attribute (*)

    Select the custom attribute configured in Prerequisites (*)

    authorityGroupId Unspecified authorityGroupId

    Custom Attribute

    Select the custom attribute configured in Prerequisites

    (*) You can also select existing TrustLogin member information (such as email address or last name).

    08.png

  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

Note: The SAML app must be configured in advance by an administrator.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.