How to Configure SAML Authentication for kintone

Note: SAML authentication can be used with the web browser, desktop app, and mobile app.

Note: Prior application with kintone (Cybozu) is required.

Note: You must register the same email address as your TrustLogin account in the "Login Name" of your kintone (Cybozu) user.

Note: Please refer to the manual provided by Cybozu for the most up-to-date configuration steps.

Configuring SAML Authentication in cybozu.com
https://jp.cybozu.help/general/ja/admin/list_saml/saml_settings.html

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    kintone_saml_01.png

  2. On the "Register Corporate App" screen, search for and select "kintone (SAML)".

    kintone_saml_02.png

  3. Make a note of the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
    (This will be needed later when configuring the kintone side.)
    kintone_saml_03.png

Now, switch to configuring the kintone side.
Do not click the "Register" button yet — open the kintone admin screen in a separate tab.

kintone Configuration

  1. Log in to the kintone admin screen with administrator privileges and select "cybozu.com Common Admin".
  2. From the left menu, select "Security > Login".

    kintone_saml_04.png

  3. Check "Enable SAML Authentication" under "SAML Authentication", and register the information you noted in step 3 of "TrustLogin Admin Page Configuration" above as follows.

    TrustLogin cybozu.com
    Identity Provider URL Identity Provider's SSO endpoint URL
    https://portal.trustlogin.com URL to redirect to after logging out of kintone
    Certificate The public key certificate used by the Identity Provider for signing

    After registering, click "Save" to save the settings.

    kintone_saml_05.png

  4. Download the metadata from "Download Service Provider Metadata".

    kintone_saml_06.png

TrustLogin Admin Page Configuration (Continued)

Return to the TrustLogin admin page again.

4. In "Service Provider Settings", enter [the cybozu login URL] into "Login URL",
  and upload the metadata you downloaded in step 4 of "kintone Configuration" above
  into "Metadata".

cybozu_saml_07.png

 5. Click the "Register" button.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "kintone (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension and confirm that login is successful.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "kintone (SAML)" app.
  2. Click "Add Member", select the user you want to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for kintone

Note: SAML authentication can be used with the web browser, desktop app, and mobile app.

Note: Prior application with kintone (Cybozu) is required.

Note: You must register the same email address as your TrustLogin account in the "Login Name" of your kintone (Cybozu) user.

Note: Please refer to the manual provided by Cybozu for the most up-to-date configuration steps.

Configuring SAML Authentication in cybozu.com
https://jp.cybozu.help/general/ja/admin/list_saml/saml_settings.html

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    kintone_saml_01.png

  2. On the "Register Corporate App" screen, search for and select "kintone (SAML)".

    kintone_saml_02.png

  3. Make a note of the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
    (This will be needed later when configuring the kintone side.)
    kintone_saml_03.png

Now, switch to configuring the kintone side.
Do not click the "Register" button yet — open the kintone admin screen in a separate tab.

kintone Configuration

  1. Log in to the kintone admin screen with administrator privileges and select "cybozu.com Common Admin".
  2. From the left menu, select "Security > Login".

    kintone_saml_04.png

  3. Check "Enable SAML Authentication" under "SAML Authentication", and register the information you noted in step 3 of "TrustLogin Admin Page Configuration" above as follows.

    TrustLogin cybozu.com
    Identity Provider URL Identity Provider's SSO endpoint URL
    https://portal.trustlogin.com URL to redirect to after logging out of kintone
    Certificate The public key certificate used by the Identity Provider for signing

    After registering, click "Save" to save the settings.

    kintone_saml_05.png

  4. Download the metadata from "Download Service Provider Metadata".

    kintone_saml_06.png

TrustLogin Admin Page Configuration (Continued)

Return to the TrustLogin admin page again.

4. In "Service Provider Settings", enter [the cybozu login URL] into "Login URL",
  and upload the metadata you downloaded in step 4 of "kintone Configuration" above
  into "Metadata".

cybozu_saml_07.png

 5. Click the "Register" button.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "kintone (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension and confirm that login is successful.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "kintone (SAML)" app.
  2. Click "Add Member", select the user you want to add from the member list, and click the "Register" button to add them.