Initial Setup Steps for Identity Provisioning with Zitadel

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Zitadel.

Note: For detailed instructions on operating Zitadel, please refer to the documentation provided by Zitadel.

Item Details
Pre-check
  • Zitadel administrator privileges are required.
Setup Flow / Manual

Note: After connecting TrustLogin and Zitadel using the steps on this page,
 please proceed to configuring user synchronization.

Provisioning Target Supports user provisioning
Supports group provisioning
SAML Authentication Setup Manual
Notes
  • None in particular

Setup Steps

Zitadel Settings

  1. Log in to Zitadel with administrator privileges, then click "Users" from the top of the screen or the menu.
    [Zitadel]_ID_01.png

  2. On the screen that appears, click "Service Users > New".
    [Zitadel]_ID_02.png

  3. Enter any username in "User Name" and "Name", then click "Create".

    [Zitadel]_ID_03.png

  4. On the details screen of the service user you created, click "Personal Access Tokens".

    [Zitadel]_ID_04.png

  5. Click "New".

    [Zitadel]_ID_05.png

  6. If you want to set an expiration date, enter the date. If you want it to remain valid indefinitely, leave the field blank. After configuring, click "Add".

    [Zitadel]_ID_06.png

  7. Check the value of the new token displayed on the screen and copy it to your clipboard.
    (The value you copy here will be used in the TrustLogin settings later.)

    [Zitadel]_ID_07.png

  8. Click "Organization" from the top of the screen or the menu.

    [Zitadel]_ID_08.png

  9. On the organization settings screen, click "+".

    [Zitadel]_ID_09.png

  10. In the search field that appears, enter the name of the service user you created earlier to search for it, then select the target service user from the search results.

    [Zitadel]_ID_10.png

  11. Select "Org Owner" and "Org User Manager" as the roles to grant. Click "Add" to grant the roles.

    [Zitadel]_ID_11.png

  12. Check the Zitadel instance name from the URL shown in your browser's address bar. Copy the "<instance name>" portion corresponding to "https://<instance name>.zitadel.cloud/" in the URL.

    [Zitadel]_ID_12.png

  13. From the information in the "Organization" tab, check the value corresponding to the organization's "Resource ID" and copy it as the "org-id".
    (The value you copy here will be used as the "org-id" in the TrustLogin settings later.)

    [Zitadel]_ID_13.png

    This completes the preparation on the Zitadel side. Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png

  2. Click "Add Service".
    IDProvServiceCommon02.png
  3. On the Add Service screen, search for and select "Zitadel", then click the "Add" button.
    [Zitadel]_ID_14.png
  4. You will be redirected to the "Identity Provisioning > Zitadel" page.
    Click the "Edit" button.

    [Zitadel]_ID_15.png

  5. Open "Access Settings", enter the following values for the settings items, and click "Save".

    Connection URL

    https://<instance name*1>.zitadel.cloud/scim/v2/<org-id*2>

    *1 Instance name: the value obtained in step 12 of Zitadel Settings
    *2 org-id: the organization's Resource ID obtained in step 13 of Zitadel Settings

    Access Token The value of the token copied in step 7 of Zitadel Settings
    [Zitadel]_ID_16.png

  6. Click the "Connect" button in the upper right of the screen.

    [Zitadel]_ID_17.png

  7. Once the button status updates to "Connected", the initial setup is complete.

    [Zitadel]_ID_18.png

    Next step: The manual for configuring user synchronization is available here

Values You Can Configure in Attribute Mapping

You can map any attribute on the TrustLogin side to any attribute on the Zitadel side.
For configuration instructions, see here

Available Default Functions

Initial Setup Steps for Identity Provisioning with Zitadel

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Zitadel.

Note: For detailed instructions on operating Zitadel, please refer to the documentation provided by Zitadel.

Item Details
Pre-check
  • Zitadel administrator privileges are required.
Setup Flow / Manual

Note: After connecting TrustLogin and Zitadel using the steps on this page,
 please proceed to configuring user synchronization.

Provisioning Target Supports user provisioning
Supports group provisioning
SAML Authentication Setup Manual
Notes
  • None in particular

Setup Steps

Zitadel Settings

  1. Log in to Zitadel with administrator privileges, then click "Users" from the top of the screen or the menu.
    [Zitadel]_ID_01.png

  2. On the screen that appears, click "Service Users > New".
    [Zitadel]_ID_02.png

  3. Enter any username in "User Name" and "Name", then click "Create".

    [Zitadel]_ID_03.png

  4. On the details screen of the service user you created, click "Personal Access Tokens".

    [Zitadel]_ID_04.png

  5. Click "New".

    [Zitadel]_ID_05.png

  6. If you want to set an expiration date, enter the date. If you want it to remain valid indefinitely, leave the field blank. After configuring, click "Add".

    [Zitadel]_ID_06.png

  7. Check the value of the new token displayed on the screen and copy it to your clipboard.
    (The value you copy here will be used in the TrustLogin settings later.)

    [Zitadel]_ID_07.png

  8. Click "Organization" from the top of the screen or the menu.

    [Zitadel]_ID_08.png

  9. On the organization settings screen, click "+".

    [Zitadel]_ID_09.png

  10. In the search field that appears, enter the name of the service user you created earlier to search for it, then select the target service user from the search results.

    [Zitadel]_ID_10.png

  11. Select "Org Owner" and "Org User Manager" as the roles to grant. Click "Add" to grant the roles.

    [Zitadel]_ID_11.png

  12. Check the Zitadel instance name from the URL shown in your browser's address bar. Copy the "<instance name>" portion corresponding to "https://<instance name>.zitadel.cloud/" in the URL.

    [Zitadel]_ID_12.png

  13. From the information in the "Organization" tab, check the value corresponding to the organization's "Resource ID" and copy it as the "org-id".
    (The value you copy here will be used as the "org-id" in the TrustLogin settings later.)

    [Zitadel]_ID_13.png

    This completes the preparation on the Zitadel side. Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png

  2. Click "Add Service".
    IDProvServiceCommon02.png
  3. On the Add Service screen, search for and select "Zitadel", then click the "Add" button.
    [Zitadel]_ID_14.png
  4. You will be redirected to the "Identity Provisioning > Zitadel" page.
    Click the "Edit" button.

    [Zitadel]_ID_15.png

  5. Open "Access Settings", enter the following values for the settings items, and click "Save".

    Connection URL

    https://<instance name*1>.zitadel.cloud/scim/v2/<org-id*2>

    *1 Instance name: the value obtained in step 12 of Zitadel Settings
    *2 org-id: the organization's Resource ID obtained in step 13 of Zitadel Settings

    Access Token The value of the token copied in step 7 of Zitadel Settings
    [Zitadel]_ID_16.png

  6. Click the "Connect" button in the upper right of the screen.

    [Zitadel]_ID_17.png

  7. Once the button status updates to "Connected", the initial setup is complete.

    [Zitadel]_ID_18.png

    Next step: The manual for configuring user synchronization is available here

Values You Can Configure in Attribute Mapping

You can map any attribute on the TrustLogin side to any attribute on the Zitadel side.
For configuration instructions, see here

Available Default Functions