How to Configure SAML Authentication for LINE WORKS

Item

Details

Prior Confirmation

  • Prior configuration in LINE WORKS is required.

  • The External Key of the LINE WORKS member and the TrustLogin email address must match.
  • For the latest configuration steps, please refer to the manual provided by LINE WORKS.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side Settings

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • SAML SSO is available on the LINE WORKS Standard plan or higher. (As of June 2025)

Table of Contents:

Preparation

Configuring the TrustLogin Admin Page

Configuring LINE WORKS

Configuring the TrustLogin Admin Page (Continued)

Configuring TrustLogin User Settings

How to Log In from the Mobile App

Preparation

For existing members on the LINE WORKS side, set the email address used as the TrustLogin identifier as the External Key.

  1. Log in to the Developer Console and open "Organization Integration" in the left menu.
    00_1.png

  2. Download the CSV file from "Download List" under "Member External Key Mapping".
    00_2.png

  3. In the downloaded CSV file, add and edit the "External Key" column with the corresponding TrustLogin email address for each member, then upload it using the "Upload" button.
    00_4.png

  4. Confirm that the "External Key" has been applied correctly.
    00_5.png


Note: After enabling SAML SSO, you will be able to edit the External Key of existing members and set the External Key when adding new members from the Member Management page in the Admin screen.

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "LINE WORKS (SAML)".
    02.png

  3. Note the value of the "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png


  4. Convert the extension of the downloaded certificate to ".pem".

At this point, move on to the configuration on the LINE WORKS side.
Do not click the "Register" button yet — open LINE WORKS in a separate window.

Configuring LINE WORKS

  1. Open the Developer Console, open "SSO" > "WORKS as SP" in the left menu, and select "SAML" for "SSO Type".
    04.png

  2. Configure each item as follows, then click the "Apply" button.
    Web Login URL The "Identity Provider URL" obtained from TrustLogin
    Logout URL https://portal.trustlogin.com/
    IdP-issued Certificate The "Certificate" obtained from TrustLogin (converted to PEM format)
    Set External Browser

    Turn "Apply" ON


    05.png

    When you click "Apply", a message will be displayed. Please check it and select "OK".
    06.png

Return to the TrustLogin Admin Page again.


Configuring the TrustLogin Admin Page (Continued)

  1. In the "Service Provider Settings" section, enter the following into the 3 input fields for "Login URL" and "ACS URL for Service".
    Login URL ① Your LINE WORKS domain name/Works group name
    (the "group.xx" part of id@group.xx)
    Login URL ② The part after "https://" in the URL of the LINE WORKS service you want to redirect to after login
    (Example)
    Home   home.worksmobile.com

    Talk   talk.worksmobile.com
    Calendar calendar.worksmobile.com
    ACS URL for Service Your LINE WORKS domain name/Works group name
    (the "group.xx" part of id@group.xx)

    07.png

  2. Click the "Register" button to save.

Configuring TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "LINE WORKS (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an administrator adds a member

  1. On the "Admin Page > Apps" menu, search for and click the "LINE WORKS (SAML)" app.
  2. Click "Add Member", select the user you want to add from the member list, and click the "Register" button to add them.

How to Log In from the Mobile/Desktop App

  1. Open the login screen of the mobile app, enter your "Mobile Number or ID", and tap the "Log In" button.
    When you launch the desktop app, a login screen window will open. Similarly, enter your "Mobile Number or ID" and click the "Log In" button.
    09.PNG

  2. You will be redirected to an external browser. If you are not logged in to TrustLogin, an authentication screen will open; complete the authentication to finish logging in.

How to Configure SAML Authentication for LINE WORKS

Item

Details

Prior Confirmation

  • Prior configuration in LINE WORKS is required.

  • The External Key of the LINE WORKS member and the TrustLogin email address must match.
  • For the latest configuration steps, please refer to the manual provided by LINE WORKS.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side Settings

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • SAML SSO is available on the LINE WORKS Standard plan or higher. (As of June 2025)

Table of Contents:

Preparation

Configuring the TrustLogin Admin Page

Configuring LINE WORKS

Configuring the TrustLogin Admin Page (Continued)

Configuring TrustLogin User Settings

How to Log In from the Mobile App

Preparation

For existing members on the LINE WORKS side, set the email address used as the TrustLogin identifier as the External Key.

  1. Log in to the Developer Console and open "Organization Integration" in the left menu.
    00_1.png

  2. Download the CSV file from "Download List" under "Member External Key Mapping".
    00_2.png

  3. In the downloaded CSV file, add and edit the "External Key" column with the corresponding TrustLogin email address for each member, then upload it using the "Upload" button.
    00_4.png

  4. Confirm that the "External Key" has been applied correctly.
    00_5.png


Note: After enabling SAML SSO, you will be able to edit the External Key of existing members and set the External Key when adding new members from the Member Management page in the Admin screen.

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "LINE WORKS (SAML)".
    02.png

  3. Note the value of the "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png


  4. Convert the extension of the downloaded certificate to ".pem".

At this point, move on to the configuration on the LINE WORKS side.
Do not click the "Register" button yet — open LINE WORKS in a separate window.

Configuring LINE WORKS

  1. Open the Developer Console, open "SSO" > "WORKS as SP" in the left menu, and select "SAML" for "SSO Type".
    04.png

  2. Configure each item as follows, then click the "Apply" button.
    Web Login URL The "Identity Provider URL" obtained from TrustLogin
    Logout URL https://portal.trustlogin.com/
    IdP-issued Certificate The "Certificate" obtained from TrustLogin (converted to PEM format)
    Set External Browser

    Turn "Apply" ON


    05.png

    When you click "Apply", a message will be displayed. Please check it and select "OK".
    06.png

Return to the TrustLogin Admin Page again.


Configuring the TrustLogin Admin Page (Continued)

  1. In the "Service Provider Settings" section, enter the following into the 3 input fields for "Login URL" and "ACS URL for Service".
    Login URL ① Your LINE WORKS domain name/Works group name
    (the "group.xx" part of id@group.xx)
    Login URL ② The part after "https://" in the URL of the LINE WORKS service you want to redirect to after login
    (Example)
    Home   home.worksmobile.com

    Talk   talk.worksmobile.com
    Calendar calendar.worksmobile.com
    ACS URL for Service Your LINE WORKS domain name/Works group name
    (the "group.xx" part of id@group.xx)

    07.png

  2. Click the "Register" button to save.

Configuring TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "LINE WORKS (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an administrator adds a member

  1. On the "Admin Page > Apps" menu, search for and click the "LINE WORKS (SAML)" app.
  2. Click "Add Member", select the user you want to add from the member list, and click the "Register" button to add them.

How to Log In from the Mobile/Desktop App

  1. Open the login screen of the mobile app, enter your "Mobile Number or ID", and tap the "Log In" button.
    When you launch the desktop app, a login screen window will open. Similarly, enter your "Mobile Number or ID" and click the "Log In" button.
    09.PNG

  2. You will be redirected to an external browser. If you are not logged in to TrustLogin, an authentication screen will open; complete the authentication to finish logging in.