How to Configure SAML Authentication for Sasuke Works

Item

Details

Pre-check

  • Prior configuration in Sasuke Works is required.
  • You must create an account in Sasuke Works using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by Sasuke Works.
Name ID Email address
Custom attribute Note: For instructions on how to configure a custom attribute, click here
SP-side Configuration Configured by the administrator
Request configuration from the SP
Provisioning API-based Provisioning supported (account management available in TrustLogin)
SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:
Enabled for all users (users can choose to use SAML authentication together with password authentication)

Notes

None in particular

Table of Contents:

TrustLogin Admin Page Settings

Sasuke Works Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. Search on the "Register Company App" screen and select "Sasuke Works (SAML)".
    2026-05-13_18-09-25.png
  3. Note the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring Sasuke Works.
Do not click the "Register" button yet — open Sasuke Works in a separate window.

Sasuke Works Settings

  1. Log in to Sasuke Works and click "Contract Details" from the gear icon in the upper right.
    2026-05-13_17-57-38.png
  2. Click "Security Settings > Change Settings".

    2026-05-13_17-57-58.png

  3. Configure the "External Authentication Integration" section as follows and click the "Register" button.

    External Authentication Integration Enabled
    Existing Login Feature

    We recommend enabling this when configuring SSO

    Note: Setting this to "Disabled" will prevent logging in with an ID and password from the login screen, making SSO the only login method. If you want to disable it, we recommend doing so only after configuring SSO and confirming that it works correctly.

    External Service TrustLogin
    ACS (Consumer) URL Copy and keep a note of this
    Audience (EntityID) Copy and keep a note of this
    IdP Entity ID The "Issuer / Entity ID" noted from TrustLogin
    IdP SSO URL The "IdP URL" noted from TrustLogin
    X.509 Certificate Paste the contents of the certificate downloaded from TrustLogin
    2026-05-13_18-20-33.png

Now return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Entity ID The "Audience (EntityID)" noted from Sasuke Works
    ACS URL to Service The "ACS (Consumer) URL" noted from Sasuke Works

    2026-05-13_18-12-28.png

  2. Save the settings by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by an administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Sasuke Works (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Sasuke Works (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

① Logging in via SP-Initiated SSO

  1. Open the Sasuke Works login URL and click the "TrustLogin" button.
    2026-05-14_13-16-35.png
  2. You will be redirected to the TrustLogin login screen, where you can log in via SSO.

How to Configure SAML Authentication for Sasuke Works

Item

Details

Pre-check

  • Prior configuration in Sasuke Works is required.
  • You must create an account in Sasuke Works using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by Sasuke Works.
Name ID Email address
Custom attribute Note: For instructions on how to configure a custom attribute, click here
SP-side Configuration Configured by the administrator
Request configuration from the SP
Provisioning API-based Provisioning supported (account management available in TrustLogin)
SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:
Enabled for all users (users can choose to use SAML authentication together with password authentication)

Notes

None in particular

Table of Contents:

TrustLogin Admin Page Settings

Sasuke Works Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. Search on the "Register Company App" screen and select "Sasuke Works (SAML)".
    2026-05-13_18-09-25.png
  3. Note the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring Sasuke Works.
Do not click the "Register" button yet — open Sasuke Works in a separate window.

Sasuke Works Settings

  1. Log in to Sasuke Works and click "Contract Details" from the gear icon in the upper right.
    2026-05-13_17-57-38.png
  2. Click "Security Settings > Change Settings".

    2026-05-13_17-57-58.png

  3. Configure the "External Authentication Integration" section as follows and click the "Register" button.

    External Authentication Integration Enabled
    Existing Login Feature

    We recommend enabling this when configuring SSO

    Note: Setting this to "Disabled" will prevent logging in with an ID and password from the login screen, making SSO the only login method. If you want to disable it, we recommend doing so only after configuring SSO and confirming that it works correctly.

    External Service TrustLogin
    ACS (Consumer) URL Copy and keep a note of this
    Audience (EntityID) Copy and keep a note of this
    IdP Entity ID The "Issuer / Entity ID" noted from TrustLogin
    IdP SSO URL The "IdP URL" noted from TrustLogin
    X.509 Certificate Paste the contents of the certificate downloaded from TrustLogin
    2026-05-13_18-20-33.png

Now return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Entity ID The "Audience (EntityID)" noted from Sasuke Works
    ACS URL to Service The "ACS (Consumer) URL" noted from Sasuke Works

    2026-05-13_18-12-28.png

  2. Save the settings by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by an administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Sasuke Works (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Sasuke Works (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

① Logging in via SP-Initiated SSO

  1. Open the Sasuke Works login URL and click the "TrustLogin" button.
    2026-05-14_13-16-35.png
  2. You will be redirected to the TrustLogin login screen, where you can log in via SSO.