This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Zitadel.
Note: For detailed instructions on operating Zitadel, please refer to the documentation provided by Zitadel.
| Item | Details | |
| Pre-check |
|
|
| Setup Flow / Manual |
Note: After connecting TrustLogin and Zitadel using the steps on this page, |
|
| Provisioning Target | 〇 | Supports user provisioning |
| ー | Supports group provisioning | |
| SAML Authentication Setup Manual | ー | |
| Notes |
|
|
Setup Steps
Zitadel Settings
-
Log in to Zitadel with administrator privileges, then click "Users" from the top of the screen or the menu.
-
On the screen that appears, click "Service Users > New".
-
Enter any username in "User Name" and "Name", then click "Create".
-
On the details screen of the service user you created, click "Personal Access Tokens".
-
Click "New".
-
If you want to set an expiration date, enter the date. If you want it to remain valid indefinitely, leave the field blank. After configuring, click "Add".
-
Check the value of the new token displayed on the screen and copy it to your clipboard.
(The value you copy here will be used in the TrustLogin settings later.) -
Click "Organization" from the top of the screen or the menu.
-
On the organization settings screen, click "+".
-
In the search field that appears, enter the name of the service user you created earlier to search for it, then select the target service user from the search results.
-
Select "Org Owner" and "Org User Manager" as the roles to grant. Click "Add" to grant the roles.
-
Check the Zitadel instance name from the URL shown in your browser's address bar. Copy the "<instance name>" portion corresponding to "https://<instance name>.zitadel.cloud/" in the URL.
-
From the information in the "Organization" tab, check the value corresponding to the organization's "Resource ID" and copy it as the "org-id".
(The value you copy here will be used as the "org-id" in the TrustLogin settings later.)This completes the preparation on the Zitadel side. Next, configure the settings on the TrustLogin side.
TrustLogin Settings
Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
open "Settings" next to "Identity Provisioning".
- Click "Add Service".
- On the Add Service screen, search for and select "Zitadel", then click the "Add" button.
-
You will be redirected to the "Identity Provisioning > Zitadel" page.
Click the "Edit" button.
-
Open "Access Settings", enter the following values for the settings items, and click "Save".
Connection URL https://<instance name*1>.zitadel.cloud/scim/v2/<org-id*2>
*1 Instance name: the value obtained in step 12 of Zitadel Settings
*2 org-id: the organization's Resource ID obtained in step 13 of Zitadel SettingsAccess Token The value of the token copied in step 7 of Zitadel Settings -
Click the "Connect" button in the upper right of the screen.
-
Once the button status updates to "Connected", the initial setup is complete.
Next step: The manual for configuring user synchronization is available here
Values You Can Configure in Attribute Mapping
You can map any attribute on the TrustLogin side to any attribute on the Zitadel side.
For configuration instructions, see here
Available Default Functions
- default functions common to all services can be specified.