How to Configure SAML JIT for Sigma (Sigma Computing)

Item

Details

Pre-check

  • Pre-configuration is required in Sigma Computing (hereafter Sigma).
  • For the latest configuration steps, please refer to the manual provided by Sigma.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, see here
SP Configuration Configured by the Administrator
Request SP to configure
Provisioning API-based Provisioning supported (Account management available in TrustLogin)
SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin mobile web app in-app browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin mobile web app in-app browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Enabled for all users (SAML authentication and password authentication can be used together)

Notes

  • Click here for Sigma's SSO configuration manual.

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

Sigma Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Log in via SP-Initiated SSO

Prerequisites

Create Groups and Assign Members

Note: If synchronization between Sigma teams and TrustLogin groups is not needed, this setting is not required. Proceed to the next item.

Create groups in TrustLogin to map to Sigma teams, and assign members. The team names in Sigma and the group names in TrustLogin must match.

For how to create groups and assign members, please refer to the following page.
Register a Group

[Example Configuration]

If the team names in Sigma are "Team1" "Team2", create groups with the same names "Team1" "Team2" in TrustLogin and assign members.

  • Sigma team settings
    2026-05-19_11-10-42.png
  • TrustLogin group settings
    2026-05-19_11-11-49.png

This way, when users in the "Team1" "Team2" groups in TrustLogin perform SAML SSO to Sigma, they are automatically added to the respective "Team1" "Team2" teams in Sigma.
If a member is removed or moved from a group in TrustLogin, they will also be removed or moved from the team in Sigma after SAML SSO.


Custom Attribute Settings

Set custom attributes in TrustLogin member information to specify the role to assign to Sigma users.

Note: The attribute name is optional.
Note: If not configured, the "View" role will be assigned on the Sigma side.
Note: For Sigma roles, please refer to here.

[TrustLogin Custom Attribute Configuration Example]

2026-05-19_13-31-37.png

For configuration methods, please refer to the following pages.

Custom Attribute Configuration Method (Individual Registration)
Custom Attribute Configuration Method (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin and open the "Admin Page > App" menu, then click the "Register SAML App" button at the top right of the screen.
    01.png
  2. Register the "Application Name" and "Icon" (optional).
    2026-05-19_15-21-19.png
  3. Copy and note down the "Identity Provider URL" value under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, proceed to the Sigma settings.
Do not click the "Save" button yet; open Sigma in a separate window.

Sigma Settings

  1. Log in to Sigma and click "Administration".
    2026-05-18_16-41-46.png
  2. Open "Authentication" and click "+Add authentication methods".

    2026-05-18_16-42-22.png

  3. Configure "Authentication methods" as follows and save with "Save".

    Authentication method SAML
    Name Any name of your choice, e.g.: TrustLogin
    Note: The name set here will be displayed on the SSO login button when using SP-initiated SSO.
    Service provider entity ID copy and note down
    Assertion consumer service URL copy and note down
    Relay state copy and note down
    Identity provider login URL* Enter the "Identity Provider URL" copied from TrustLogin
    Identity provider X.509 certificate* Paste the content of the "Certificate" copied from TrustLogin
    2026-05-18_16-53-20.png


    Note: If you want to restrict login to SSO only, you can disable password-based login by clicking "Delete" for "Authentication method: Password". It is recommended to disable it after completing the SSO configuration and verifying the connection.2026-05-19_15-34-32.png

Return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.

    Redirect URL after SP authentication success Enter the "Relay state" copied from Sigma
    Name ID value Member - email
    Entity ID Enter the "Service provider entity ID" copied from Sigma
    Name ID Format emailAddress
    ACS URL Enter the "Assertion consumer service URL" copied from Sigma

    2026-05-18_17-12-01.png

  2. Click the "Specify Custom Attributes" button in "SAML Attribute Settings", then click "Add SAML Attribute" to add rows (attributes) and configure as follows.

    Service Provider Attributes TrustLogin (IdP) Attributes
    Attribute Name Attribute Type Attribute Name Attribute Value
    firstName Unspecified firstName Member First Name
    lastName Unspecified lastName Member Last Name
    userRole Unspecified userRole Custom attribute Attribute name with Sigma role configured
    userGroups Unspecified userGroups Group Select the configured group names and add all with the "+" button

    2026-05-18_16-53-51.png

  3. Save by clicking the "Save" button.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. In the "Admin Page > App" menu, search for the custom SAML app you created and click it.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log in via SP-Initiated SSO

Open the Sigma login URL and click "Sign in with ○○" (the "Name" configured in Sigma's SSO settings) to start the SSO login.

2026-05-18_16-54-23.png

How to Configure SAML JIT for Sigma (Sigma Computing)

Item

Details

Pre-check

  • Pre-configuration is required in Sigma Computing (hereafter Sigma).
  • For the latest configuration steps, please refer to the manual provided by Sigma.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, see here
SP Configuration Configured by the Administrator
Request SP to configure
Provisioning API-based Provisioning supported (Account management available in TrustLogin)
SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin mobile web app in-app browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin mobile web app in-app browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Enabled for all users (SAML authentication and password authentication can be used together)

Notes

  • Click here for Sigma's SSO configuration manual.

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

Sigma Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Log in via SP-Initiated SSO

Prerequisites

Create Groups and Assign Members

Note: If synchronization between Sigma teams and TrustLogin groups is not needed, this setting is not required. Proceed to the next item.

Create groups in TrustLogin to map to Sigma teams, and assign members. The team names in Sigma and the group names in TrustLogin must match.

For how to create groups and assign members, please refer to the following page.
Register a Group

[Example Configuration]

If the team names in Sigma are "Team1" "Team2", create groups with the same names "Team1" "Team2" in TrustLogin and assign members.

  • Sigma team settings
    2026-05-19_11-10-42.png
  • TrustLogin group settings
    2026-05-19_11-11-49.png

This way, when users in the "Team1" "Team2" groups in TrustLogin perform SAML SSO to Sigma, they are automatically added to the respective "Team1" "Team2" teams in Sigma.
If a member is removed or moved from a group in TrustLogin, they will also be removed or moved from the team in Sigma after SAML SSO.


Custom Attribute Settings

Set custom attributes in TrustLogin member information to specify the role to assign to Sigma users.

Note: The attribute name is optional.
Note: If not configured, the "View" role will be assigned on the Sigma side.
Note: For Sigma roles, please refer to here.

[TrustLogin Custom Attribute Configuration Example]

2026-05-19_13-31-37.png

For configuration methods, please refer to the following pages.

Custom Attribute Configuration Method (Individual Registration)
Custom Attribute Configuration Method (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin and open the "Admin Page > App" menu, then click the "Register SAML App" button at the top right of the screen.
    01.png
  2. Register the "Application Name" and "Icon" (optional).
    2026-05-19_15-21-19.png
  3. Copy and note down the "Identity Provider URL" value under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, proceed to the Sigma settings.
Do not click the "Save" button yet; open Sigma in a separate window.

Sigma Settings

  1. Log in to Sigma and click "Administration".
    2026-05-18_16-41-46.png
  2. Open "Authentication" and click "+Add authentication methods".

    2026-05-18_16-42-22.png

  3. Configure "Authentication methods" as follows and save with "Save".

    Authentication method SAML
    Name Any name of your choice, e.g.: TrustLogin
    Note: The name set here will be displayed on the SSO login button when using SP-initiated SSO.
    Service provider entity ID copy and note down
    Assertion consumer service URL copy and note down
    Relay state copy and note down
    Identity provider login URL* Enter the "Identity Provider URL" copied from TrustLogin
    Identity provider X.509 certificate* Paste the content of the "Certificate" copied from TrustLogin
    2026-05-18_16-53-20.png


    Note: If you want to restrict login to SSO only, you can disable password-based login by clicking "Delete" for "Authentication method: Password". It is recommended to disable it after completing the SSO configuration and verifying the connection.2026-05-19_15-34-32.png

Return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.

    Redirect URL after SP authentication success Enter the "Relay state" copied from Sigma
    Name ID value Member - email
    Entity ID Enter the "Service provider entity ID" copied from Sigma
    Name ID Format emailAddress
    ACS URL Enter the "Assertion consumer service URL" copied from Sigma

    2026-05-18_17-12-01.png

  2. Click the "Specify Custom Attributes" button in "SAML Attribute Settings", then click "Add SAML Attribute" to add rows (attributes) and configure as follows.

    Service Provider Attributes TrustLogin (IdP) Attributes
    Attribute Name Attribute Type Attribute Name Attribute Value
    firstName Unspecified firstName Member First Name
    lastName Unspecified lastName Member Last Name
    userRole Unspecified userRole Custom attribute Attribute name with Sigma role configured
    userGroups Unspecified userGroups Group Select the configured group names and add all with the "+" button

    2026-05-18_16-53-51.png

  3. Save by clicking the "Save" button.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. In the "Admin Page > App" menu, search for the custom SAML app you created and click it.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log in via SP-Initiated SSO

Open the Sigma login URL and click "Sign in with ○○" (the "Name" configured in Sigma's SSO settings) to start the SSO login.

2026-05-18_16-54-23.png