How to Configure SAML JIT for Lucid

Item

Details

Pre-check

  • Prior setup is required on the Lucid side.
  • For the latest setup instructions, please refer to the manual provided by Lucid.
Name ID Email address
Custom attribute Note: For instructions on how to configure custom attributes, seehere
SP-Side Settings Configured by the administrator
Request the SP to configure settings
Provisioning Supportsprovisioningvia API (account management possible in TrustLogin)
Supports SAML JITprovisioning(account management possible in TrustLogin; user deletion not supported)
None (accounts are created individually in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation Status by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App (Lucidchart, Lucidspark)
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App (Lucidchart, Lucidspark)
Scope of SAML Authentication Enabled for all users (SAML authentication only)
Enabled for all users (can choose to use SAML authentication together with password authentication)

Notes

  • A user's first and last name are synced only when the account is newly created.
  • If an error occurs during SAML authentication, you can check the details of the applicable error on this(SAML Authentication Error List)page.

Table of Contents:

TrustLogin Admin Page Settings

Lucid Settings

TrustLogin Admin Page Settings (Continued)

Lucid Settings (Continued)

TrustLogin User Settings

How to Log In via the Mobile App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    01.png
  2. Search on the "Register Enterprise App" screen and select "Lucid (SAML)".
    2026-07-29_13-07-18.png
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

At this point, switch to configuring the Lucid side.
Do not click the "Register" button yet — open Lucid in a separate window.

Lucid Settings

  1. Open the admin screen and select "App Integrations > General > SAML > Settings".
    2026-07-29_13-09-29.png
  2. Set an arbitrary domain for the "Lucid Sign-in URL" domain, then click "Save Changes". Make a note of the domain you set here, as you will enter it in TrustLogin later.
    Under "Add Identity Provider +", upload the metadata you saved from TrustLogin.

    2026-07-29_13-18-40.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. In the "Service Provider Settings" section, enter the domain you set in Lucid into the blank "Login URL" and "Service ACS URL" fields.
    2026-07-29_14-30-13.png
  2. Click the "Register" button to save.
  3. Use "Add Member" to add and assign the currently logged-in user. Note: This will be used later for testing SSO.

Return to Lucid again.

Lucid Settings (Continued)

  1. Click "Test SAML Connection" to run the SSO test.

    2026-07-29_13-19-07.png
  2. If the following screen is displayed, the connection test was successful.
    2026-07-29_13-19-42.png
  3. If necessary, configure the "Domain Management" settings. For details, please see here.
    2026-07-29_17-30-12.png
  4. In "Security > Authentication", select the sign-in method for users and the default login method under "Default Setting", then click "Save Changes".
    Note: If you uncheck "Allow email and password" under "User Sign-in", users will no longer be able to log in with a password.

    2026-07-29_17-23-55.png

TrustLogin User Settings

① When a User Adds the App via My Page

Note: The administrator must have configured the SAML app in advance.

  1. Click the "Add App" button in "My Page".
  2. On the "Register App" screen, select "Lucid (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Lucid (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In via the Mobile App

  1. Open the mobile app and tap "Log In".
    2026-07-29_17-18-37.png
  2. Tap "Sign in with SSO".

    2026-07-29_17-18-48.png

  3. On the Lucid SSO screen, enter the domain you set, and log in.

    2026-07-29_17-19-04.png

How to Configure SAML JIT for Lucid

Item

Details

Pre-check

  • Prior setup is required on the Lucid side.
  • For the latest setup instructions, please refer to the manual provided by Lucid.
Name ID Email address
Custom attribute Note: For instructions on how to configure custom attributes, seehere
SP-Side Settings Configured by the administrator
Request the SP to configure settings
Provisioning Supportsprovisioningvia API (account management possible in TrustLogin)
Supports SAML JITprovisioning(account management possible in TrustLogin; user deletion not supported)
None (accounts are created individually in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Verified Operation Status by Device PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App (Lucidchart, Lucidspark)
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App (Lucidchart, Lucidspark)
Scope of SAML Authentication Enabled for all users (SAML authentication only)
Enabled for all users (can choose to use SAML authentication together with password authentication)

Notes

  • A user's first and last name are synced only when the account is newly created.
  • If an error occurs during SAML authentication, you can check the details of the applicable error on this(SAML Authentication Error List)page.

Table of Contents:

TrustLogin Admin Page Settings

Lucid Settings

TrustLogin Admin Page Settings (Continued)

Lucid Settings (Continued)

TrustLogin User Settings

How to Log In via the Mobile App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    01.png
  2. Search on the "Register Enterprise App" screen and select "Lucid (SAML)".
    2026-07-29_13-07-18.png
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

At this point, switch to configuring the Lucid side.
Do not click the "Register" button yet — open Lucid in a separate window.

Lucid Settings

  1. Open the admin screen and select "App Integrations > General > SAML > Settings".
    2026-07-29_13-09-29.png
  2. Set an arbitrary domain for the "Lucid Sign-in URL" domain, then click "Save Changes". Make a note of the domain you set here, as you will enter it in TrustLogin later.
    Under "Add Identity Provider +", upload the metadata you saved from TrustLogin.

    2026-07-29_13-18-40.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. In the "Service Provider Settings" section, enter the domain you set in Lucid into the blank "Login URL" and "Service ACS URL" fields.
    2026-07-29_14-30-13.png
  2. Click the "Register" button to save.
  3. Use "Add Member" to add and assign the currently logged-in user. Note: This will be used later for testing SSO.

Return to Lucid again.

Lucid Settings (Continued)

  1. Click "Test SAML Connection" to run the SSO test.

    2026-07-29_13-19-07.png
  2. If the following screen is displayed, the connection test was successful.
    2026-07-29_13-19-42.png
  3. If necessary, configure the "Domain Management" settings. For details, please see here.
    2026-07-29_17-30-12.png
  4. In "Security > Authentication", select the sign-in method for users and the default login method under "Default Setting", then click "Save Changes".
    Note: If you uncheck "Allow email and password" under "User Sign-in", users will no longer be able to log in with a password.

    2026-07-29_17-23-55.png

TrustLogin User Settings

① When a User Adds the App via My Page

Note: The administrator must have configured the SAML app in advance.

  1. Click the "Add App" button in "My Page".
  2. On the "Register App" screen, select "Lucid (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Lucid (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In via the Mobile App

  1. Open the mobile app and tap "Log In".
    2026-07-29_17-18-37.png
  2. Tap "Sign in with SSO".

    2026-07-29_17-18-48.png

  3. On the Lucid SSO screen, enter the domain you set, and log in.

    2026-07-29_17-19-04.png