AI-Q SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in AI-Q is required.

  • Please refer to the manual provided by AI-Q for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.                                  
     01.png

  2. Search on the "Register Company App" screen and select "AI-Q (SAML)".

    AI-Q__01.jpg

  3. Make a note of the "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", then download the certificate from "Download Certificate".

    AI-Q_03.jpg

Now, switch to configuring the AI-Q side.
Do not click the "Register" button yet — open the AI-Q admin page in a separate tab.

AI-Q Settings

  1. Log in to AI-Q with an administrator account, then open "Environment Settings > SAML Settings" from the "Main Menu".

    AI-Q_04.jpg

  2. ① Click the "Register/Update" button under "Register Information to SP".                  
    AI-Q_05.jpg

  3. Register the information you noted down in step 3 of "TrustLogin Admin Page Settings" above as follows. After registering, click "Save". 
    Identity Provider's Entity ID (entityID) The "Issuer / Entity ID" you noted from TrustLogin
    Identity Provider's Login URL (SingleSignOnService) The "Identity Provider URL" you noted from TrustLogin
    Identity Provider's Certificate (X509Data) Open the "certificate" you noted from TrustLogin and paste it in
    Login Name Policy (NameIDFormat) urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    AI-Q_06.jpg
  4. ② Click "Metadata (SP)" under "Register Information to IdP" to download the metadata.                  AI-Q_07.jpg

    Return to the TrustLogin admin page again.

                                

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata you noted from AI-Q to "Metadata" under "Service Provider Settings".   AI-Q_08.jpg      
  2. Click the "Register" button.
  3. Search for and select the "AI-Q (SAML)" app in the "Admin Page > App" menu.
  4. Under "Add Member", add the user who has SAML configured, then click "Register".AI-Q_15.jpg AI-Q_16.jpg
  5. Log out of TrustLogin and return to the SAML settings on the AI-Q side again.     

AI-Q Settings (Continued)

  1. ③ Click "Communication Test to IdP", then click the "SAML Test" button. (Alternatively, note down the URL below "SAML Test" and access it while logged out.)
    Note: Please perform the SAML test while logged out of TrustLogin.AI-Q_09.jpg
  2. You will be redirected to the TrustLogin login page. Please log in to TrustLogin.AI-Q_11.jpg
  3. After confirming the message "SAML settings are incomplete. Please configure them.", log in to AI-Q with your email address and password.AI-Q_10.jpg
  4. After logging in, open "Environment Settings > SAML Settings" from the "Main Menu" again.
  5. ④ Confirm that the "Register/Update" and "Delete" buttons are displayed to the right of "Configure User Management", then click "Register/Update".AI-Q_12.jpg
  6. Configure each item on the SAML settings screen as follows, then click "Save".
    ID used for login (email) NameID (entered automatically)
    Username 1 obtained from IdP information NameID (entered automatically)
    User's password when using SSO Any password
    User's role when using SSO Select Administrator or User
    Automatically create a user with the IdP account Create
    AI-Q_SAMLJIT.jpg
  7. ⑤ Click "Set Up Link", note down the URL of the "Login page for SSO", then open a separate browser, access it, and log in.AI-Q_14.jpg

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "AI-Q (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an administrator adds a member

  1. Search for and click the "AI-Q" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

AI-Q SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in AI-Q is required.

  • Please refer to the manual provided by AI-Q for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.                                  
     01.png

  2. Search on the "Register Company App" screen and select "AI-Q (SAML)".

    AI-Q__01.jpg

  3. Make a note of the "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", then download the certificate from "Download Certificate".

    AI-Q_03.jpg

Now, switch to configuring the AI-Q side.
Do not click the "Register" button yet — open the AI-Q admin page in a separate tab.

AI-Q Settings

  1. Log in to AI-Q with an administrator account, then open "Environment Settings > SAML Settings" from the "Main Menu".

    AI-Q_04.jpg

  2. ① Click the "Register/Update" button under "Register Information to SP".                  
    AI-Q_05.jpg

  3. Register the information you noted down in step 3 of "TrustLogin Admin Page Settings" above as follows. After registering, click "Save". 
    Identity Provider's Entity ID (entityID) The "Issuer / Entity ID" you noted from TrustLogin
    Identity Provider's Login URL (SingleSignOnService) The "Identity Provider URL" you noted from TrustLogin
    Identity Provider's Certificate (X509Data) Open the "certificate" you noted from TrustLogin and paste it in
    Login Name Policy (NameIDFormat) urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    AI-Q_06.jpg
  4. ② Click "Metadata (SP)" under "Register Information to IdP" to download the metadata.                  AI-Q_07.jpg

    Return to the TrustLogin admin page again.

                                

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata you noted from AI-Q to "Metadata" under "Service Provider Settings".   AI-Q_08.jpg      
  2. Click the "Register" button.
  3. Search for and select the "AI-Q (SAML)" app in the "Admin Page > App" menu.
  4. Under "Add Member", add the user who has SAML configured, then click "Register".AI-Q_15.jpg AI-Q_16.jpg
  5. Log out of TrustLogin and return to the SAML settings on the AI-Q side again.     

AI-Q Settings (Continued)

  1. ③ Click "Communication Test to IdP", then click the "SAML Test" button. (Alternatively, note down the URL below "SAML Test" and access it while logged out.)
    Note: Please perform the SAML test while logged out of TrustLogin.AI-Q_09.jpg
  2. You will be redirected to the TrustLogin login page. Please log in to TrustLogin.AI-Q_11.jpg
  3. After confirming the message "SAML settings are incomplete. Please configure them.", log in to AI-Q with your email address and password.AI-Q_10.jpg
  4. After logging in, open "Environment Settings > SAML Settings" from the "Main Menu" again.
  5. ④ Confirm that the "Register/Update" and "Delete" buttons are displayed to the right of "Configure User Management", then click "Register/Update".AI-Q_12.jpg
  6. Configure each item on the SAML settings screen as follows, then click "Save".
    ID used for login (email) NameID (entered automatically)
    Username 1 obtained from IdP information NameID (entered automatically)
    User's password when using SSO Any password
    User's role when using SSO Select Administrator or User
    Automatically create a user with the IdP account Create
    AI-Q_SAMLJIT.jpg
  7. ⑤ Click "Set Up Link", note down the URL of the "Login page for SSO", then open a separate browser, access it, and log in.AI-Q_14.jpg

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "AI-Q (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an administrator adds a member

  1. Search for and click the "AI-Q" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.