How to Configure SAML JIT (Group Mapping) for Claude

Item

Details

Prior Confirmation

  • Prior configuration is required on the Claude side.
  • To configure SSO, domain verification is required in Claude.
  • For the latest configuration steps, please refer to the manual provided by Claude.
Name ID Email address
  Custom attribute Note: For instructions on how to configure custom attributes, see here
SP-side Settings Configured by the administrator
  Request configuration from the SP
Provisioning   API-based Provisioning supported (accounts can be managed in TrustLogin)
SAML JIT Provisioning supported (accounts can be managed in TrustLogin; user deletion not supported)
Note: For configuration steps when provisioning is not required, see here
  None (accounts are created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation Status by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App Internal Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App Internal Browser
Android - Native App
Scope of SAML Authentication Enabled for all users (SAML authentication only)
Other:
Enabled only for users of domains where SAML authentication is applied on the SP side (SAML authentication and email authentication can be used together)

Notes

  • This manual was verified using the Team plan of Claude.
  • This manual describes the procedure for enabling group mapping with Claude's SAML JIT provisioning.
  • If the group (role) assignment is changed on the TrustLogin side, it will also be changed on the Claude side.
    If multiple groups are assigned to a single user, the role with greater privileges will be granted.
  • After creating a group in TrustLogin, be sure to assign the TrustLogin administrator who will configure SSO to a group with the Owner role. If not assigned, it may not be possible to enable the group on the Claude side.
  • If a user who has not been assigned to a group logs in via SAML JIT, they will not be able to access the organization.
  • If a user who was previously assigned to a group and logged in via SAML JIT logs in again via SAML JIT after being removed from the group, they will lose access to the organization and will be removed from the organization.
  • For the manual on the Claude side, see here.

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings

Claude Settings

TrustLogin Admin Page Settings (Continued)

Claude Settings (Continued)

TrustLogin User Settings

Login Method

 

Preparation

Create groups in TrustLogin to map to roles in Claude, and assign members to them. The roles on the Claude side are "Owner," "Admin," and "User."
The group name can be anything, but we recommend using a group name that clearly indicates the role.
After creating the group, be sure to assign the TrustLogin administrator who will configure SSO to the group with the Owner role. If not assigned, it may not be possible to enable the group on the Claude side.

Example TrustLogin group names:

  • Owner: Owner
  • Admin: Admin
  • User: User

    2026-06-19_18-44-47.png


For instructions on how to create groups and assign members, please refer to the page below.
Register a Group
 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right corner of the screen.
    jit01.png

     
  2. Configure the "Application Name" and "Icon" (optional).
    2026-06-19_17-52-39.png
     
  3. Note down the values for "Identity Provider URL" and "Issuer/Entity ID" in "Identity Provider Information," then download the certificate using the "Get Certificate" button.03.png

     
  4. Convert the extension of the downloaded certificate to ".cer."
     

Now, switch to the Claude side settings.
Do not click the "Register" button yet; open Claude in a separate window.

 

Claude Settings

  1. Log in to Claude with an Owner or Primary Owner account and open "Organization Settings."
    Click "Organization & Access > Domains > Add or Edit Domain."
    Note: If you have already added the domain for which you want to configure SSO, proceed to step 3.

    2026-06-19_14-31-14.png

     

  2. Add the domain and click "Save."

    2026-06-19_14-31-54.png
     

  3. Click "Verify" next to the domain.

    2026-06-19_14-32-17.png

     

  4. Enter the domain to verify and click "Continue."

    2026-06-18_16-25-19.png

     

  5. Set the displayed DNS record for the domain.
    Note: The method for configuring DNS records varies depending on your domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for the DNS record changes to take effect.

    2026-06-18_16-30-48.png

     

  6. Once the domain is verified, the following screen will be displayed.

    2026-06-18_16-49-23.png

     

  7. Return to the "Organization & Access" screen and click "SSO Setup" under "Authentication > Single Sign-On."

    2026-06-18_16-50-46.png

     

  8. On the "Select your identity provider" screen, select "Custom SAML."

    2026-06-18_16-51-17.png

     

  9. Set the name of the identity provider. The name can be anything.
    Example: TrustLogin, GMO TrustLogin

    2026-06-18_16-58-44.png

     

  10. In "Step 2: Create a SAML application," note down the "Assertion consumer service (ACS) URL" and "Service provider entity ID," then click "Continue."

    2026-06-18_16-59-49.png

     

  11. In Step 3: Set Identity Provider Metadata, select "Manual configuration" and configure as follows.
    After configuring, click "Continue."

    Identity provider Single Sign-On URL The "Identity Provider URL" noted from TrustLogin
    Identity provider issuer The "Issuer/Entity ID" noted from TrustLogin
    X.509 certificate Upload the "certificate" obtained from TrustLogin
    Note: the one converted to .cer
    2026-06-18_17-01-12.png

     

  12. No configuration is required for "Step 4: Configure SAML Attributes." Proceed by clicking "Continue."

    2026-06-18_17-05-19.png


Leaving the Claude settings screen open, return to the TrustLogin Admin Page again.

 

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Value for Name ID Member - email
    Entity ID The "Service provider entity ID" noted from Claude
    Name ID Format unspecified
    ACS URL to the Service The "Assertion consumer service (ACS) URL" noted from Claude
    2026-06-19_17-52-47.png

     

  2. In "SAML Attribute Settings," click the "Specify Custom Attributes" button, then use the "Add SAML Attribute" button to add rows (attributes) and configure them as follows.

    Service Provider Attributes TrustLogin (IdP) Attributes
    Specified Attribute Name Attribute Type Attribute Name   Attribute Value
    id Unspecified id Member Email address
    email Unspecified email Member Email address
    firstName Unspecified firstName Member First name
    lastName Unspecified lastName Member Last name
    groups Unspecified groups Group Select the configured group names and add them all using the "+" button

    2026-06-19_18-06-10.png
     

  3. Click the "Register" button to save.
     
  4. Add and assign the administrator who is configuring SSO using "Add Member" in the SAML app. Note: This will be used later for SSO testing.
     

Return to the Claude settings screen again.
 

Claude Settings (Continued)

  1. In "Step 5: Test Single Sign-On," click "Continue to sign-In" to run the SSO connection test.

    2026-06-18_17-05-45.png

     

  2. If the SSO connection test succeeds, the following screen will be displayed.
    Note: The connection test result may open in a separate browser window.

    2026-06-18_17-07-03.png

     

  3. Return to the "Organization & Access" screen and select "Just-in-Time (JIT)."
    Turn on the "Enable Group Mapping" toggle, and from the "+" button, set the same group name as the TrustLogin group name created in "Preparation", then click "Save."
    2026-06-19_17-54-06.png
     
  4. If you want to enforce SSO-only login, turn on the "Require SSO for Claude" toggle under "Authentication."
    Note: This setting is optional. If you turn on the toggle, we recommend doing so after confirming the connection and notifying your organization internally.
    2026-06-19_15-56-35.png

 

TrustLogin User Settings

① When a user adds it from My Page

Note: The administrator must have configured the SAML app in advance.

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
     

 

Login Method

① When logging in via "IdP-initiated"

When logging in via IdP-initiated, an email address confirmation screen will be displayed. Confirm the email address and click "Continue as XXXX@XXXX.com."

2026-06-18_17-18-33.png



 

② When logging in via "SP-initiated"

Open the Claude login URL and enter your email address. If the email address is subject to SSO, the "Continue with SSO" button will be displayed. Click "Continue with SSO" to log in via SSO.
Note: If the "Require SSO for Claude" toggle is turned on in the Claude settings, the "Continue with Email" button will not be displayed.
Note: For login from the desktop app as well, please log in using "Continue with SSO."

2026-06-19_16-05-00.png

 

③ How to log in from the native app

  1. Open the app and enter your email address.
    2026-06-19_16-09-37.png
     
  2. Click "SSO" to start SSO login.

    2026-06-19_16-09-47.png

How to Configure SAML JIT (Group Mapping) for Claude

Item

Details

Prior Confirmation

  • Prior configuration is required on the Claude side.
  • To configure SSO, domain verification is required in Claude.
  • For the latest configuration steps, please refer to the manual provided by Claude.
Name ID Email address
  Custom attribute Note: For instructions on how to configure custom attributes, see here
SP-side Settings Configured by the administrator
  Request configuration from the SP
Provisioning   API-based Provisioning supported (accounts can be managed in TrustLogin)
SAML JIT Provisioning supported (accounts can be managed in TrustLogin; user deletion not supported)
Note: For configuration steps when provisioning is not required, see here
  None (accounts are created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation Status by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App Internal Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App Internal Browser
Android - Native App
Scope of SAML Authentication Enabled for all users (SAML authentication only)
Other:
Enabled only for users of domains where SAML authentication is applied on the SP side (SAML authentication and email authentication can be used together)

Notes

  • This manual was verified using the Team plan of Claude.
  • This manual describes the procedure for enabling group mapping with Claude's SAML JIT provisioning.
  • If the group (role) assignment is changed on the TrustLogin side, it will also be changed on the Claude side.
    If multiple groups are assigned to a single user, the role with greater privileges will be granted.
  • After creating a group in TrustLogin, be sure to assign the TrustLogin administrator who will configure SSO to a group with the Owner role. If not assigned, it may not be possible to enable the group on the Claude side.
  • If a user who has not been assigned to a group logs in via SAML JIT, they will not be able to access the organization.
  • If a user who was previously assigned to a group and logged in via SAML JIT logs in again via SAML JIT after being removed from the group, they will lose access to the organization and will be removed from the organization.
  • For the manual on the Claude side, see here.

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings

Claude Settings

TrustLogin Admin Page Settings (Continued)

Claude Settings (Continued)

TrustLogin User Settings

Login Method

 

Preparation

Create groups in TrustLogin to map to roles in Claude, and assign members to them. The roles on the Claude side are "Owner," "Admin," and "User."
The group name can be anything, but we recommend using a group name that clearly indicates the role.
After creating the group, be sure to assign the TrustLogin administrator who will configure SSO to the group with the Owner role. If not assigned, it may not be possible to enable the group on the Claude side.

Example TrustLogin group names:

  • Owner: Owner
  • Admin: Admin
  • User: User

    2026-06-19_18-44-47.png


For instructions on how to create groups and assign members, please refer to the page below.
Register a Group
 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right corner of the screen.
    jit01.png

     
  2. Configure the "Application Name" and "Icon" (optional).
    2026-06-19_17-52-39.png
     
  3. Note down the values for "Identity Provider URL" and "Issuer/Entity ID" in "Identity Provider Information," then download the certificate using the "Get Certificate" button.03.png

     
  4. Convert the extension of the downloaded certificate to ".cer."
     

Now, switch to the Claude side settings.
Do not click the "Register" button yet; open Claude in a separate window.

 

Claude Settings

  1. Log in to Claude with an Owner or Primary Owner account and open "Organization Settings."
    Click "Organization & Access > Domains > Add or Edit Domain."
    Note: If you have already added the domain for which you want to configure SSO, proceed to step 3.

    2026-06-19_14-31-14.png

     

  2. Add the domain and click "Save."

    2026-06-19_14-31-54.png
     

  3. Click "Verify" next to the domain.

    2026-06-19_14-32-17.png

     

  4. Enter the domain to verify and click "Continue."

    2026-06-18_16-25-19.png

     

  5. Set the displayed DNS record for the domain.
    Note: The method for configuring DNS records varies depending on your domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for the DNS record changes to take effect.

    2026-06-18_16-30-48.png

     

  6. Once the domain is verified, the following screen will be displayed.

    2026-06-18_16-49-23.png

     

  7. Return to the "Organization & Access" screen and click "SSO Setup" under "Authentication > Single Sign-On."

    2026-06-18_16-50-46.png

     

  8. On the "Select your identity provider" screen, select "Custom SAML."

    2026-06-18_16-51-17.png

     

  9. Set the name of the identity provider. The name can be anything.
    Example: TrustLogin, GMO TrustLogin

    2026-06-18_16-58-44.png

     

  10. In "Step 2: Create a SAML application," note down the "Assertion consumer service (ACS) URL" and "Service provider entity ID," then click "Continue."

    2026-06-18_16-59-49.png

     

  11. In Step 3: Set Identity Provider Metadata, select "Manual configuration" and configure as follows.
    After configuring, click "Continue."

    Identity provider Single Sign-On URL The "Identity Provider URL" noted from TrustLogin
    Identity provider issuer The "Issuer/Entity ID" noted from TrustLogin
    X.509 certificate Upload the "certificate" obtained from TrustLogin
    Note: the one converted to .cer
    2026-06-18_17-01-12.png

     

  12. No configuration is required for "Step 4: Configure SAML Attributes." Proceed by clicking "Continue."

    2026-06-18_17-05-19.png


Leaving the Claude settings screen open, return to the TrustLogin Admin Page again.

 

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.

    Value for Name ID Member - email
    Entity ID The "Service provider entity ID" noted from Claude
    Name ID Format unspecified
    ACS URL to the Service The "Assertion consumer service (ACS) URL" noted from Claude
    2026-06-19_17-52-47.png

     

  2. In "SAML Attribute Settings," click the "Specify Custom Attributes" button, then use the "Add SAML Attribute" button to add rows (attributes) and configure them as follows.

    Service Provider Attributes TrustLogin (IdP) Attributes
    Specified Attribute Name Attribute Type Attribute Name   Attribute Value
    id Unspecified id Member Email address
    email Unspecified email Member Email address
    firstName Unspecified firstName Member First name
    lastName Unspecified lastName Member Last name
    groups Unspecified groups Group Select the configured group names and add them all using the "+" button

    2026-06-19_18-06-10.png
     

  3. Click the "Register" button to save.
     
  4. Add and assign the administrator who is configuring SSO using "Add Member" in the SAML app. Note: This will be used later for SSO testing.
     

Return to the Claude settings screen again.
 

Claude Settings (Continued)

  1. In "Step 5: Test Single Sign-On," click "Continue to sign-In" to run the SSO connection test.

    2026-06-18_17-05-45.png

     

  2. If the SSO connection test succeeds, the following screen will be displayed.
    Note: The connection test result may open in a separate browser window.

    2026-06-18_17-07-03.png

     

  3. Return to the "Organization & Access" screen and select "Just-in-Time (JIT)."
    Turn on the "Enable Group Mapping" toggle, and from the "+" button, set the same group name as the TrustLogin group name created in "Preparation", then click "Save."
    2026-06-19_17-54-06.png
     
  4. If you want to enforce SSO-only login, turn on the "Require SSO for Claude" toggle under "Authentication."
    Note: This setting is optional. If you turn on the toggle, we recommend doing so after confirming the connection and notifying your organization internally.
    2026-06-19_15-56-35.png

 

TrustLogin User Settings

① When a user adds it from My Page

Note: The administrator must have configured the SAML app in advance.

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
     

 

Login Method

① When logging in via "IdP-initiated"

When logging in via IdP-initiated, an email address confirmation screen will be displayed. Confirm the email address and click "Continue as XXXX@XXXX.com."

2026-06-18_17-18-33.png



 

② When logging in via "SP-initiated"

Open the Claude login URL and enter your email address. If the email address is subject to SSO, the "Continue with SSO" button will be displayed. Click "Continue with SSO" to log in via SSO.
Note: If the "Require SSO for Claude" toggle is turned on in the Claude settings, the "Continue with Email" button will not be displayed.
Note: For login from the desktop app as well, please log in using "Continue with SSO."

2026-06-19_16-05-00.png

 

③ How to log in from the native app

  1. Open the app and enter your email address.
    2026-06-19_16-09-37.png
     
  2. Click "SSO" to start SSO login.

    2026-06-19_16-09-47.png