How to Configure SAML Authentication for KING OF TIME

Item

Details

Prerequisites

  • Prior configuration is required in KING OF TIME.

  • You must create an account in KING OF TIME using the same email address as TrustLogin.

  • You must be using the "New Domain" in KING OF TIME. For details, please check here.
  • For the latest configuration steps, please refer to the manual provided by KING OF TIME.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    01.png

  2. On the "Register Company App" screen, search and select "[For SAML Configuration] KING OF TIME." 001.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information."

    03.png

Now switch to the configuration on the KING OF TIME side. Please open KING OF TIME in a separate window.

KING OF TIME Configuration

  1. Log in with a KING OF TIME administrator account.
  2. From the left menu, select "Settings > Other."         04.png
  3. Select "Options." 05.png
  4. From "External Account Integration," select "Use" under "SAML Account Integration," then select "Allow" for both "        
  5. From the "SAML Account Integration Settings List," click "+ New Registration."                                                                                                               07.png                      

  6. Enter any "IdP Code" and "IdP Name" of your choosing.
    Copy and paste the metadata content downloaded from TrustLogin into "IdP's metadata."
    .                       08.png                       

  7. Click the "Register" button to return to the TrustLogin configuration.

TrustLogin Admin Page Configuration (Continued)

  1. KING OF TIME accounts have both a "New Domain" and an "Old Domain." For details, see here. Check the URL of your KING OF TIME login screen, and enter the alphanumeric characters at the beginning of the URL (s2 or s3) into the "Login URL" field under "Service Provider Settings."   09_02_.png             
  2. Upload the metadata you downloaded from KING OF TIME via "Select Metadata."

  3. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. In "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "[For SAML Configuration] KING OF TIME," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.
  4. Click the app from "My Page" or the "browser extension" and check whether login succeeds.
  5. Please also register "[For SAML Login] KING OF TIME" using the same method as above.

When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "[For SAML Configuration] KING OF TIME" and "[For SAML Login] KING OF TIME" apps.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In to KING OF TIME

If you want to access KING OF TIME via SAML authentication from TrustLogin's My Page or the browser extension, you can enable SAML login to KING OF TIME by separately registering the "[For SAML Login] KING OF TIME" app.

  1. On the "Register Company App" screen, search and select "[For SAML Login] KING OF TIME." 002.png
  2. Rewrite the URL using the alphanumeric characters (s2 or s3) from the beginning of the KING OF TIME login URL you entered earlier, then click the "Register" button.  13.png

  3. In "My Page," click the "Add App" button.
  4. On the "Register App" screen, select "[For SAML Login] KING OF TIME," and click the "Next" button in the upper right of the screen.
  5. Enter the "User Type (Administrator or Employee)" and "Company Code."12.pngYou can check the company code in the upper right of the admin screen or the employee screen.14.png
  6. If you want to change the "Display Name," enter a new one, then click the "Save" button.

  7. Click the app from "My Page" or the "browser extension" and check whether login succeeds. If you have configured multiple IdPs, select the destination IdP from the dropdown on the screen.

    Note: After configuring SAML in "[For SAML Configuration] KING OF TIME," enter the "User Type (Administrator or Employee)" and "Company Code" in "[For SAML Login] KING OF TIME" and register them.
    Note: By having both administrators and users register the "[For SAML Configuration] KING OF TIME" and "[For SAML Login] KING OF TIME" apps, single sign-on from TrustLogin becomes possible.
    Note: "[For SAML Login] KING OF TIME" can be used with PC browsers and Android - Chrome.
    Note: It can also be used with the iOS in-app browser and Android in-app browser, but you will be asked to log in to TrustLogin again.
    Note: On iOS - Safari, you will need to manually enter the company code.

How to Log In to the My Recorder Screen

  1. If you want to navigate to the KING OF TIME My Recorder screen via SAML authentication, please use the "[For SAML Login] My Recorder" app.
    KOT.png

  2. Enter your My Recorder URL in the login URL field and register it.KOT01.png

    Note: "[For SAML Login] My Recorder" can be used with PC browsers.
    Note: It can also be used with the iOS in-app browser and Android in-app browser, but you will be asked to log in to TrustLogin again.
    Note: On Android - Chrome, after clicking the "Go to External ID Login Screen" button, the company code is automatically filled in and you are taken to the My Recorder screen. On iOS - Safari, you will need to manually enter the company code.

How to Configure SAML Authentication for KING OF TIME

Item

Details

Prerequisites

  • Prior configuration is required in KING OF TIME.

  • You must create an account in KING OF TIME using the same email address as TrustLogin.

  • You must be using the "New Domain" in KING OF TIME. For details, please check here.
  • For the latest configuration steps, please refer to the manual provided by KING OF TIME.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    01.png

  2. On the "Register Company App" screen, search and select "[For SAML Configuration] KING OF TIME." 001.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information."

    03.png

Now switch to the configuration on the KING OF TIME side. Please open KING OF TIME in a separate window.

KING OF TIME Configuration

  1. Log in with a KING OF TIME administrator account.
  2. From the left menu, select "Settings > Other."         04.png
  3. Select "Options." 05.png
  4. From "External Account Integration," select "Use" under "SAML Account Integration," then select "Allow" for both "        
  5. From the "SAML Account Integration Settings List," click "+ New Registration."                                                                                                               07.png                      

  6. Enter any "IdP Code" and "IdP Name" of your choosing.
    Copy and paste the metadata content downloaded from TrustLogin into "IdP's metadata."
    .                       08.png                       

  7. Click the "Register" button to return to the TrustLogin configuration.

TrustLogin Admin Page Configuration (Continued)

  1. KING OF TIME accounts have both a "New Domain" and an "Old Domain." For details, see here. Check the URL of your KING OF TIME login screen, and enter the alphanumeric characters at the beginning of the URL (s2 or s3) into the "Login URL" field under "Service Provider Settings."   09_02_.png             
  2. Upload the metadata you downloaded from KING OF TIME via "Select Metadata."

  3. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. In "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "[For SAML Configuration] KING OF TIME," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.
  4. Click the app from "My Page" or the "browser extension" and check whether login succeeds.
  5. Please also register "[For SAML Login] KING OF TIME" using the same method as above.

When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "[For SAML Configuration] KING OF TIME" and "[For SAML Login] KING OF TIME" apps.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In to KING OF TIME

If you want to access KING OF TIME via SAML authentication from TrustLogin's My Page or the browser extension, you can enable SAML login to KING OF TIME by separately registering the "[For SAML Login] KING OF TIME" app.

  1. On the "Register Company App" screen, search and select "[For SAML Login] KING OF TIME." 002.png
  2. Rewrite the URL using the alphanumeric characters (s2 or s3) from the beginning of the KING OF TIME login URL you entered earlier, then click the "Register" button.  13.png

  3. In "My Page," click the "Add App" button.
  4. On the "Register App" screen, select "[For SAML Login] KING OF TIME," and click the "Next" button in the upper right of the screen.
  5. Enter the "User Type (Administrator or Employee)" and "Company Code."12.pngYou can check the company code in the upper right of the admin screen or the employee screen.14.png
  6. If you want to change the "Display Name," enter a new one, then click the "Save" button.

  7. Click the app from "My Page" or the "browser extension" and check whether login succeeds. If you have configured multiple IdPs, select the destination IdP from the dropdown on the screen.

    Note: After configuring SAML in "[For SAML Configuration] KING OF TIME," enter the "User Type (Administrator or Employee)" and "Company Code" in "[For SAML Login] KING OF TIME" and register them.
    Note: By having both administrators and users register the "[For SAML Configuration] KING OF TIME" and "[For SAML Login] KING OF TIME" apps, single sign-on from TrustLogin becomes possible.
    Note: "[For SAML Login] KING OF TIME" can be used with PC browsers and Android - Chrome.
    Note: It can also be used with the iOS in-app browser and Android in-app browser, but you will be asked to log in to TrustLogin again.
    Note: On iOS - Safari, you will need to manually enter the company code.

How to Log In to the My Recorder Screen

  1. If you want to navigate to the KING OF TIME My Recorder screen via SAML authentication, please use the "[For SAML Login] My Recorder" app.
    KOT.png

  2. Enter your My Recorder URL in the login URL field and register it.KOT01.png

    Note: "[For SAML Login] My Recorder" can be used with PC browsers.
    Note: It can also be used with the iOS in-app browser and Android in-app browser, but you will be asked to log in to TrustLogin again.
    Note: On Android - Chrome, after clicking the "Go to External ID Login Screen" button, the company code is automatically filled in and you are taken to the My Recorder screen. On iOS - Safari, you will need to manually enter the company code.