Item |
Details |
|
|---|---|---|
Prior Confirmation |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For instructions on how to configure custom attributes, see here | ||
| SP-side Settings | 〇 | Configured by the administrator |
| Request configuration from the SP | ||
| Provisioning | API-based Provisioning supported (accounts can be managed in TrustLogin) | |
| 〇 |
SAML JIT Provisioning supported (accounts can be managed in TrustLogin; user deletion not supported) Note: For configuration steps when provisioning is not required, see here |
|
| None (accounts are created in each system) | ||
| Access Method | 〇 | SP-Initiated SSO |
| 〇 | IdP-Initiated SSO | |
| Verified Operation Status by Device | 〇 | PC - Browser |
| 〇 | PC - Desktop App | |
| 〇 | iOS - Standard Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App Internal Browser | |
| 〇 | iOS - Native App | |
| 〇 | Android - Standard Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App Internal Browser | |
| 〇 |
Android - Native App |
|
| Scope of SAML Authentication | ー | Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled only for users of domains where SAML authentication is applied on the SP side (SAML authentication and email authentication can be used together) |
|
Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Settings |
Preparation
Create groups in TrustLogin to map to roles in Claude, and assign members to them. The roles on the Claude side are "Owner," "Admin," and "User."
The group name can be anything, but we recommend using a group name that clearly indicates the role.
After creating the group, be sure to assign the TrustLogin administrator who will configure SSO to the group with the Owner role. If not assigned, it may not be possible to enable the group on the Claude side.
Example TrustLogin group names:
- Owner: Owner
- Admin: Admin
- User: User
For instructions on how to create groups and assign members, please refer to the page below.
Register a Group
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right corner of the screen.
- Configure the "Application Name" and "Icon" (optional).
- Note down the values for "Identity Provider URL" and "Issuer/Entity ID" in "Identity Provider Information," then download the certificate using the "Get Certificate" button.
- Convert the extension of the downloaded certificate to ".cer."
Now, switch to the Claude side settings.
Do not click the "Register" button yet; open Claude in a separate window.
Claude Settings
-
Log in to Claude with an Owner or Primary Owner account and open "Organization Settings."
Click "Organization & Access > Domains > Add or Edit Domain."
Note: If you have already added the domain for which you want to configure SSO, proceed to step 3. -
Add the domain and click "Save."
-
Click "Verify" next to the domain.
-
Enter the domain to verify and click "Continue."
-
Set the displayed DNS record for the domain.
Note: The method for configuring DNS records varies depending on your domain registrar. Please refer to your domain registrar's help documentation. It may take up to 72 hours for the DNS record changes to take effect. -
Once the domain is verified, the following screen will be displayed.
-
Return to the "Organization & Access" screen and click "SSO Setup" under "Authentication > Single Sign-On."
-
On the "Select your identity provider" screen, select "Custom SAML."
-
Set the name of the identity provider. The name can be anything.
Example: TrustLogin, GMO TrustLogin -
In "Step 2: Create a SAML application," note down the "Assertion consumer service (ACS) URL" and "Service provider entity ID," then click "Continue."
-
In Step 3: Set Identity Provider Metadata, select "Manual configuration" and configure as follows.
After configuring, click "Continue."Identity provider Single Sign-On URL The "Identity Provider URL" noted from TrustLogin Identity provider issuer The "Issuer/Entity ID" noted from TrustLogin X.509 certificate Upload the "certificate" obtained from TrustLogin
Note: the one converted to .cer -
No configuration is required for "Step 4: Configure SAML Attributes." Proceed by clicking "Continue."
Leaving the Claude settings screen open, return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
-
Configure "Service Provider Settings" as follows.
Value for Name ID Member - email Entity ID The "Service provider entity ID" noted from Claude Name ID Format unspecified ACS URL to the Service The "Assertion consumer service (ACS) URL" noted from Claude -
In "SAML Attribute Settings," click the "Specify Custom Attributes" button, then use the "Add SAML Attribute" button to add rows (attributes) and configure them as follows.
Service Provider Attributes TrustLogin (IdP) Attributes Specified Attribute Name Attribute Type Attribute Name Attribute Value id Unspecified id Member Email address email Unspecified email Member Email address firstName Unspecified firstName Member First name lastName Unspecified lastName Member Last name groups Unspecified groups Group Select the configured group names and add them all using the "+" button
- Click the "Register" button to save.
- Add and assign the administrator who is configuring SSO using "Add Member" in the SAML app. Note: This will be used later for SSO testing.
Return to the Claude settings screen again.
Claude Settings (Continued)
-
In "Step 5: Test Single Sign-On," click "Continue to sign-In" to run the SSO connection test.
-
If the SSO connection test succeeds, the following screen will be displayed.
Note: The connection test result may open in a separate browser window. - Return to the "Organization & Access" screen and select "Just-in-Time (JIT)."
Turn on the "Enable Group Mapping" toggle, and from the "+" button, set the same group name as the TrustLogin group name created in "Preparation", then click "Save."
- If you want to enforce SSO-only login, turn on the "Require SSO for Claude" toggle under "Authentication."
Note: This setting is optional. If you turn on the toggle, we recommend doing so after confirming the connection and notifying your organization internally.
TrustLogin User Settings
① When a user adds it from My Page
Note: The administrator must have configured the SAML app in advance.
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an administrator adds a member
- Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
Login Method
① When logging in via "IdP-initiated"
When logging in via IdP-initiated, an email address confirmation screen will be displayed. Confirm the email address and click "Continue as XXXX@XXXX.com."
② When logging in via "SP-initiated"
Open the Claude login URL and enter your email address. If the email address is subject to SSO, the "Continue with SSO" button will be displayed. Click "Continue with SSO" to log in via SSO.
Note: If the "Require SSO for Claude" toggle is turned on in the Claude settings, the "Continue with Email" button will not be displayed.
Note: For login from the desktop app as well, please log in using "Continue with SSO."
③ How to log in from the native app
- Open the app and enter your email address.
-
Click "SSO" to start SSO login.