Skip to content

Set Up OneLogin SAML Custom Connector (Advanced) Application

Ensure that you have Administrator access to your OneLogin Account and Trust3 AI.

Follow these steps to create and configure a OneLogin application for Single Sign-On (SSO) using a SAML Custom Connector (Advanced).

Step 1: Add a New Application

  1. Log in to your OneLogin Admin Console.
  2. From the top menu, select Applications and then click Add App.
  3. In the search bar, type "SAML Custom Connector (Advanced)" and select it from the results.

Step 2: Provide Basic Information

  1. In the Info tab, provide a descriptive name for your application in the Display Name field.
    Example: Trust3 AI SSO - OneLogin
  2. (Optional) Upload a logo for the application if needed.
  3. Click Save to proceed to the next configuration step.

Step 3: Configure the SAML Settings

  1. Go to the Configuration tab.
  2. Fill in the following fields based on your SAML metadata information:
Field Value Example Description
ACS (Consumer) URL https://na.trust3ai.com/SingleSignOnService/receiveResponse The Assertion Consumer Service (ACS) URL where SAML responses will be sent.
ACS (Consumer) URL Validator https://na.trust3ai.com/SingleSignOnService/receiveResponse A regex pattern that matches your ACS URL for validation.
Login URL https://na.trust3ai.com/loginv1.html The URL for login initiation.
SAML Audience trust3ai_portal Entity ID for SAML configuration.

Step 4: Configure Parameters (Attribute Mapping)

  1. Go to the Parameters tab.
  2. Click + Add Parameter and add the following attributes to map user data:
Field Name Value to Send Include in SAML Assertion Sample Value Description
UserId UserName UserName Sends the user’s unique identifier.
Email Email Email Sends the user’s email address.
FirstName FirstName FirstName Sends the user's first name.
LastName LastName LastName Sends the user's last name.
memberOfGroupNames User Roles User Roles (Semicolon Delimited input ) This is an optional attribute that sends the list of groups the user belongs to. Select the checkbox for multi-value parameters
  1. For each parameter, ensure you select the checkbox for Include in SAML assertion.
  2. For the memberOfGroupNames parameter, in addition to selecting Include in SAML assertion, also select the checkbox for Multi-value parameter to support multiple groups.
  3. Click Save to proceed.

Step 5: Assign Users to the Application

  1. Go to the Users tab.
  2. Click + Assign and select Users or Groups.
  3. Choose the users or groups you want to assign and click Save.

Important

Ensure users are already mapped to the appropriate groups in OneLogin before assigning them to the application.

Step 6: Obtain the SAML Metadata

  1. In the SSO tab, locate the Issuer URL and SAML 2.0 Endpoint (HTTP).
  2. Copy both URLs for later use in the Trust3 AI portal.

Step 7: Review Your Configuration

  1. Review all the entered information and confirm that it is accurate.
  2. Click on the Save button.

You have successfully set up a SAML Custom Connector (Advanced) in OneLogin. This configuration is now ready to be integrated with the Trust3 AI portal for Single Sign-On (SSO).

Configure OneLogin in your Trust3 AI account.

In Trust3 AI, follow these steps to access the Single Sign-On settings:

  1. Go to the Settings menu.
  2. Navigate to Identity.
  3. Enable Single Sign-On.

Reference image from Trust3 AI for better guidance: Trust3 AI portal SSO settings

Display Name Description Example Value Optional/Required
Entity Id Entity ID for SAML configuration trust3ai_portal Required
Identity Provider Url Identity Provider URL https://example.onelogin.com/trust/saml2/http-post/sso/12345678-abcd-efgh-ijkl-9876543210ab Required
Identity Provider Metadata Metadata (XML file) sso_saml_darth.xml Required
UserName Attribute UserName attribute for SAML user UserId Required
Email Attribute Email attribute for SAML user Email Required
FirstName Attribute FirstName attribute for SAML user FirstName Optional
LastName Attribute LastName attribute for SAML user LastName Optional

Username Conversion in SSO

This setting determines how usernames are generated during SSO login when the Username Attribute value contains an email address.

Username Format Options

  • When the toggle is ON: The system uses the email prefix (the part before @) as the username. Example: jane.doe@xyz.comjane.doe

  • When the toggle is OFF: The system uses the full email address as the username. Example: jane.doe@xyz.comjane.doe@xyz.com

Important Considerations

Possible Conflict: Email Already in Use

A conflict may occur if the email address is already associated with another user in the system. This may prevent successful login or account linking during SSO authentication.

Example Scenario: When a user attempts to log in with email jane.doe@xyz.com, but this email is already associated with username jane.doe, the login will fail due to the conflict.

Resolution Steps: An administrator must delete the existing user from Settings → Users, then ask the user to sign in via SSO again.

Configuration Impact

  • New SSO logins will use the configured username format
  • Existing users will be affected by this change on their next login attempt.

Troubleshooting

If you experience issues with SSO login, refer to the SSO Login Troubleshooting Guide for detailed steps and solutions.

Important

  • Entity ID: Used to configure the Identity Provider (IdP).
  • Identity Provider URL: URL obtained in Step 6, where users will be redirected for SSO login.
  • Identity Provider Metadata: Use the Metadata XML file downloaded in Step 6 for seamless SSO configuration.
  • User Attributes: Ensure that the correct user attributes (UserId, Email, FirstName, LastName) are mapped from OneLogin to Trust3 AI.

These variables ensure seamless integration between OneLogin and Trust3 AI for SAML-SSO.

Role Mapping For OneLogin

Role mapping allows you to translate roles or groups from your OneLogin Identity Provider (IdP) into specific roles within Trust3 AI. This ensures that users have the correct permissions and access when they log into Trust3 AI.

What is Role Name Attributes?

This attribute in your Identity Provider (IdP) contains the user's roles or group information. It identifies the roles or groups the user belongs to in the IdP.

What is Role Mapping?

This configuration maps roles or groups from the Identity Provider (IdP) to corresponding roles in Trust3 AI. If a specific role from the Identity Provider (IdP) matches a role defined in the role mapping configuration, that role is assigned to the user in Trust3 AI. If no mapping is defined, the default role, ROLE_USER, is automatically assigned to the user.

Variable Name Description Example
Role Name Attribute Role name attributes for user. memberOfGroupNames
Role Mapping Role mapping for user. Identity Provider (IdP) Role: example_role → Example Role: ACCOUNT_ROLE

Reference image of Role Mapping from Trust3 AI: Trust3 AI portal SSO role mapping

Example:

  • Identity Provider (IdP) Role or Group: one_role_admin
  • Mapped Trust3 AI Role: ACCOUNT_ADMIN

In this example, if a user has the role one_role_admin in OneLogin, they will automatically be assigned the ACCOUNT_ADMIN role in Trust3 AI.

Important

New Users:
Role mapping only applies to newly created users after the mapping has been configured.

By properly configuring role mapping, you ensure that users are granted appropriate access levels within Trust3 AI based on their roles or group memberships from the Identity Provider (IdP). This simplifies user management and ensures seamless integration with your organization’s existing identity infrastructure.

Once the configuration is complete, you can test the setup by attempting to log in to the Trust3 AI using your OneLogin credentials. This will help verify that the Single Sign-On (SSO) integration is working correctly.