Item |
Description |
|
|---|---|---|
Prerequisites |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For instructions on how to configure custom attributes, clickhere | ||
| SP-Side Configuration | 〇 | Configured by the administrator |
| Request the SP to configure it | ||
| Provisioning | Supportsprovisioningvia API (account management possible in TrustLogin) | |
| 〇 |
Supports SAML JITprovisioning(account management possible in TrustLogin; user deletion not possible) Note: For instructions on how to configure SAML JIT (with group mapping), clickhere Note: For instructions on how to configure without provisioning, clickhere |
|
| None (create accounts in each system) | ||
| Access Method | 〇 | SP-Initiated SSO |
| 〇 | IdP-Initiated SSO | |
| Verified Device Compatibility | 〇 | PC - Browser |
| 〇 | PC - Desktop App | |
| 〇 | iOS - Standard Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App In-App Browser | |
| 〇 | iOS - Native App | |
| 〇 | Android - Standard Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App In-App Browser | |
| 〇 |
Android - Native App |
|
| SAML Authentication Scope | ー | Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled only for users in domains where SAML authentication is applied on the SP side (both SAML authentication and email authentication can be used together) |
|
Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Configuration TrustLogin Admin Page Configuration (Continued) |
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Enterprise App Registration" screen, search for and select "Claude (SAML)".
- Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
- Convert the extension of the downloaded certificate to ".cer".
Now, switch to configuring Claude.
Do not click the "Register" button yet — open Claude in a separate window.
Claude Configuration
-
Log in to Claude with an Owner or Primary Owner account and open "Organization Settings".
Click "Organization & Access > Domains > Add or Edit Domain".
Note: If you have already added the domain for which you want to configure SSO, proceed to step 3. -
Add the domain and click "Save".
-
Click "Verify" next to the domain.
-
Enter the domain you want to verify and click "Continue".
-
Set the displayed DNS record on the domain.
Note: The method for configuring DNS records varies by domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for DNS record changes to propagate. -
Once the domain is verified, the following screen will be displayed.
-
Return to the "Organization & Access" screen and click "SSO Setup" under "Authentication > Single Sign-On".
-
On the "Select your identity provider" screen, select "Custom SAML".
-
Set a name for the identity provider. You can use any name you like.
Example: TrustLogin, GMO TrustLogin -
On "Step 2: Create a SAML application", note down the "Assertion consumer service (ACS) URL" and "Service provider entity ID", then click "Continue".
-
On "Step 3: Set Identity Provider Metadata", select "Manual configuration" and configure it as follows.
After configuring, click "Continue".Identity provider Single Sign-On URL The "IdP URL" you noted down from TrustLogin Identity provider issuer The "Issuer/Entity ID" you noted down from TrustLogin X.509 certificate Upload the "certificate" you downloaded from TrustLogin
Note: the one converted to .cer -
No configuration is needed for "Step 4: Configure SAML Attributes". Click "Continue" to proceed.
Leaving the Claude configuration screen open, return to the TrustLogin Admin Page again.
TrustLogin Admin Page Configuration (Continued)
-
Configure "Service Provider Settings" as follows.
Entity ID The "Service provider entity ID" you noted down from Claude ACS URL for the Service The "Assertion consumer service (ACS) URL" you noted down from Claude
- Click the "Register" button to save.
- Use "Add Member" to add and assign the currently logged-in user. Note: This will be used later for the SSO test.
Return to the Claude configuration screen again.
Claude Configuration (Continued)
-
On "Step 5: Test Single Sign-On", click "Continue to sign-In" to run the SSO connection test.
-
If the SSO connection test succeeds, the following screen will be displayed.
Note: The connection test result may open in a separate browser window. - Return to the "Organization & Access" screen, select "Just-in-Time (JIT)", and click "Save".
Note: Leave "Enable group mapping" turned off. For instructions on how to enable group mapping, please refer to here.
- If you want to enforce SSO-only login, return to the "Organization & Access" screen and turn on the "Require SSO for Claude" toggle under "Authentication".
Note: This setting is optional. If you turn on the toggle, we recommend doing so only after the connection has been confirmed and your organization has been notified.
TrustLogin User Configuration
① When a user adds the app from My Page
Note: The administrator must have configured the SAML app beforehand.
- On "My Page", click the "Add App" button.
- On the "App Registration" screen, select "Claude (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds a member
- In the "Admin Page > Apps" menu, search for and click the "Claude (SAML)" app.
- Click "Add Member", select the user you want to add from the member list, and click the "Register" button to add them.
Login Method
① When logging in via "IdP-initiated"
When logging in via IdP-initiated, an email address confirmation screen will be displayed. Confirm the email address and click "Continue as XXXX@XXXX.com".
② When logging in via "SP-initiated"
Open the Claude login URL and enter your email address. If the email address is subject to SSO, the "Continue with SSO" button will be displayed. Click "Continue with SSO" to log in via SSO.
Note: If the "Require SSO for Claude" toggle is turned on in the Claude settings, the "Continue with email" button will not be displayed.
Note: For desktop app login as well, please log in via "Continue with SSO".
③ How to Log In via the Native App
- Open the app and enter your email address.
-
Click "SSO" to start the SSO login.