OneLogin SSO
Add a OneLogin SAML 2.0 app with the Avaloi ACS, map email as the NameID, and paste the metadata URL into Avaloi.
Create a SAML app in OneLogin, then paste its metadata URL into Avaloi. Only the Owner can save the connection.
Connect OneLogin
- Add a SAML app. In OneLogin, add a SAML 2.0 application. Set the ACS to
https://api.avaloi.com/auth/saml/{company}/acsand the start URL tohttps://api.avaloi.com/auth/saml/{company}/start. Replace{company}with your company slug. - Map email. Set the NameID to the user email. Include first and last name if you want them filled in on first login.
- Copy the metadata. Open the app's SSO tab and copy the issuer URL or metadata URL.
- Save in Avaloi. Open Company settings, then SSO. Choose SAML, paste the URL, add your domains, and save.
- Test, then enforce. Sign in through OneLogin. When that works, turn on Enforce SSO.
Quick answers
Do assertions need to be signed? Yes. Avaloi requires signed assertions from every SAML provider.
The first login created a user with no name. Add first and last name to the SAML attributes in OneLogin. Avaloi fills them in on the next login.
Members are stuck in a redirect loop. Turn Enforce SSO off, check the ACS, the metadata URL, and the NameID, then test again. See SSO.
API
GET /v1/companies/me/ssoPUT /v1/companies/me/sso
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.