How to Configure SAML Authentication for Intercom

Item

Details

Pre-check

  • Prior configuration in Intercom is required.
  • You must create an account in Intercom using the same email address as your TrustLogin account.
  • DNS configuration (domain verification) is required for SAML SSO setup.
  • For the latest setup instructions, please refer to the manual provided by Intercom.
Name ID Email address
Custom attribute Note: For instructions on configuring custom attributes, see here
SP Configuration Configured by the Administrator
Request configuration from SP
Provisioning API-based Provisioning supported (account management available via TrustLogin)
SAML JITProvisioning supported (account management available via TrustLogin; user deletion not supported)
None (accounts created in each system)
Note: For instructions on configuring provisioning, see here
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App 
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Enabled for all users (SAML authentication and password authentication can be used together)

Notes

  • If you are using client authentication, SAML authentication is not available on iOS native apps.
  • For Intercom's manual, seehere.

Table of Contents:

TrustLogin Admin Page Settings

Intercom Settings

TrustLogin Admin Page Settings (continued)

Intercom Settings (continued)

TrustLogin User Settings

How to Log In

TrustLogin Admin Page Settings

  1. Log in to TrustLogin here, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right.
    01.png
  2. Search in the "Register Enterprise App" screen and select "Intercom (SAML)".
    2026-04-09_10-47-08.png
  3. Copy and note down the "Identity Provider URL" value from "Identity Provider Information", and download the Certificate using the "Get Certificate" button.
    03.png

Now, proceed to the Intercom settings.
Do not click the "Save" button yet; open Intercom in a separate window.

Intercom Settings

  1. Log in to Intercom and select "Settings > Security".

    2026-04-09_10-48-32.png

  2. Under "Authentication Method", configure the following settings.

    Email address and Password

    Turn the toggle on

    Note: It is recommended to keep this on during the initial SAML configuration.
    Turning it off will disable password-based login.

    SAML SSO Turn the toggle on
    Base SAML URL Copy and note down
    Identity Provider Single Sign-On URL Enter the "Identity Provider URL" copied from TrustLogin
    Public Certificate Paste the contents of the "Certificate" copied from TrustLogin
    Allowed Domains Enter the domain to allow SAML SSO authentication for, then click "Add Domain"
    2026-04-09_11-02-17.png

  3. Set the displayed DNS record on your domain. Once added, click "Verify DNS Record".
    Note: DNS record configuration varies by domain registrar. Please refer to your domain registrar's help documentation. DNS record propagation can take up to 72 hours.

    2026-04-09_10-52-01.png

Return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. In "SP Configuration", enter the "Base SAML URL" noted from Intercom into both the "Entity ID" and "ACS URL" fields.

    2026-04-09_10-51-00.png

  2. Click the "Save" button to save.
  3. Add users to the SAML App.
    Note: Please add users whose email address domain is registered in Intercom's "Allowed Domains" and whose email address matches the user logged in on the Intercom side.

Return to the Intercom Admin Page.

Intercom Settings (continued)

  1. After adding the domain, click "Save".2026-04-09_11-04-38.png
  2. Click "Authenticate with Identity Provider" to test SAML SSO.2026-04-09_10-52-25.png
  3. Once authentication is successful, the SAML settings will be saved.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML App must be configured by an Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. In the "Register App" screen, select "Intercom (SAML)" and click the "Next" button in the upper right.
  3. If you wish to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. In the "Admin Page > App" menu, search for and click the "Intercom (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In

① Logging in via SP-initiated SSO

  1. Click "Sign in with SAML SSO".
    2026-04-09_12-15-34.png
  2. Enter your email address, then click "Sign in with SAML SSO".
    2026-04-09_12-15-49.png

② Logging in via the Mobile App

  1. Tap "Sign in with SAML SSO".
    2026-04-09_12-20-10.png
  2. Enter your email address and tap "Continue".
    2026-04-09_12-20-23.png

How to Configure SAML Authentication for Intercom

Item

Details

Pre-check

  • Prior configuration in Intercom is required.
  • You must create an account in Intercom using the same email address as your TrustLogin account.
  • DNS configuration (domain verification) is required for SAML SSO setup.
  • For the latest setup instructions, please refer to the manual provided by Intercom.
Name ID Email address
Custom attribute Note: For instructions on configuring custom attributes, see here
SP Configuration Configured by the Administrator
Request configuration from SP
Provisioning API-based Provisioning supported (account management available via TrustLogin)
SAML JITProvisioning supported (account management available via TrustLogin; user deletion not supported)
None (accounts created in each system)
Note: For instructions on configuring provisioning, see here
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App 
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Enabled for all users (SAML authentication and password authentication can be used together)

Notes

  • If you are using client authentication, SAML authentication is not available on iOS native apps.
  • For Intercom's manual, seehere.

Table of Contents:

TrustLogin Admin Page Settings

Intercom Settings

TrustLogin Admin Page Settings (continued)

Intercom Settings (continued)

TrustLogin User Settings

How to Log In

TrustLogin Admin Page Settings

  1. Log in to TrustLogin here, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right.
    01.png
  2. Search in the "Register Enterprise App" screen and select "Intercom (SAML)".
    2026-04-09_10-47-08.png
  3. Copy and note down the "Identity Provider URL" value from "Identity Provider Information", and download the Certificate using the "Get Certificate" button.
    03.png

Now, proceed to the Intercom settings.
Do not click the "Save" button yet; open Intercom in a separate window.

Intercom Settings

  1. Log in to Intercom and select "Settings > Security".

    2026-04-09_10-48-32.png

  2. Under "Authentication Method", configure the following settings.

    Email address and Password

    Turn the toggle on

    Note: It is recommended to keep this on during the initial SAML configuration.
    Turning it off will disable password-based login.

    SAML SSO Turn the toggle on
    Base SAML URL Copy and note down
    Identity Provider Single Sign-On URL Enter the "Identity Provider URL" copied from TrustLogin
    Public Certificate Paste the contents of the "Certificate" copied from TrustLogin
    Allowed Domains Enter the domain to allow SAML SSO authentication for, then click "Add Domain"
    2026-04-09_11-02-17.png

  3. Set the displayed DNS record on your domain. Once added, click "Verify DNS Record".
    Note: DNS record configuration varies by domain registrar. Please refer to your domain registrar's help documentation. DNS record propagation can take up to 72 hours.

    2026-04-09_10-52-01.png

Return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. In "SP Configuration", enter the "Base SAML URL" noted from Intercom into both the "Entity ID" and "ACS URL" fields.

    2026-04-09_10-51-00.png

  2. Click the "Save" button to save.
  3. Add users to the SAML App.
    Note: Please add users whose email address domain is registered in Intercom's "Allowed Domains" and whose email address matches the user logged in on the Intercom side.

Return to the Intercom Admin Page.

Intercom Settings (continued)

  1. After adding the domain, click "Save".2026-04-09_11-04-38.png
  2. Click "Authenticate with Identity Provider" to test SAML SSO.2026-04-09_10-52-25.png
  3. Once authentication is successful, the SAML settings will be saved.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML App must be configured by an Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. In the "Register App" screen, select "Intercom (SAML)" and click the "Next" button in the upper right.
  3. If you wish to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. In the "Admin Page > App" menu, search for and click the "Intercom (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In

① Logging in via SP-initiated SSO

  1. Click "Sign in with SAML SSO".
    2026-04-09_12-15-34.png
  2. Enter your email address, then click "Sign in with SAML SSO".
    2026-04-09_12-15-49.png

② Logging in via the Mobile App

  1. Tap "Sign in with SAML SSO".
    2026-04-09_12-20-10.png
  2. Enter your email address and tap "Continue".
    2026-04-09_12-20-23.png