Last updated

Create SAML application with Onelogin

This guide outlines the steps to create and configure a SAML application in Onelogin, including setup, user assignments, and metadata submission.


Step 1: Create SAML application

  1. Click on + and choose adding a SAML Application.

pingidentity

  1. Choose to Manually Enter Service Provider details.

pingidentity

  1. Copy and paste the values into the relevant fields in the SAML Configuration section.

pingidentity

  1. Go to the Configuration tab and click on the pencil for editing. Scroll down and choose emailAddress to be passed as NameID.

pingidentity

  1. Enable the application.

pingidentity

Step 2: Fill attribute statements

  1. Go to Attribute Mappings and click on the edit sign.

pingidentity

  1. The saml_subject attribute must be mapped to an email address in order for the NameID being passed as email. Additional attributes are optional.

pingidentity

Step 3: Assign users

  1. Switch to Access section and click edit.

pingidentity

  1. Choose the user groups that will have access to this application.

pingidentity

Step 4: Submit metadata

To complete the implementation of SAML SSO, you need to provide the application with your identity provider's metadata.

  1. Click on the Configuration tab of the SAML app you just created.

pingidentity

Automatic configuration

  1. Click on Download Metadata.

pingidentity

  1. Upload the file from the previous step.

Manual configuration

  1. Click on Download Signing Certificate and choose the X.509 Certificate.
  2. Paste the content of the certificate file into the Public Certificate section.
  3. Copy the Single Signon Service URL and paste the value into the SSO Endpoint field.

pingidentity

pingidentity

Step 5: Proceed with domain claiming and role assignment

  1. Click on Proceed with domain claiming and role assignment to confirm the completion the configuration of the IDP form.
  2. Follow the instructions in the Self-service SAML configuration guide to complete this step and manage authorization.