ACCESS > How to configure OneLogin for SAML and SSO
In order to integrate OneLogin SAML/SSO with your Tallyfy organization, you will need to:
- Set up and configure an OneLogin app with SAML support.
- Use the OneLogin app's settings to configure SAML on Tallyfy.
- Enable SAML for your organization on Tallyfy, to start SSO auth and user provisioning.
Create an OneLogin app for your Tallyfy organization
Preparing the new app
First make sure that you are using the Administration.
In the menu, go to
Applications > Applicationspage, then click
Search for SAML Test Connector.
Select the SAML Test Connector (Advanced) app.
Edit the Display Name, then accept other default values for now and click Save:
Configure SAML settings
First we will need to get the default SAML values from our organization in Tallyfy:
- Select our Organization's profile from the Support page.
- Scroll to Org Settings tab:
- Click on Add Configuration Details: Ignore the empty fields for now and scroll down to the existing default values.
Now, we will fill the SAML settings in OneLogin, using those values.
Go back to your OneLogin app connector page, Click on Configuration tab:
ACS (Consumer) URL: In this field, copy the value from SP ACS URL (Single Sign On URL). (number 1 in the screenshot above)
Recipient: The same URL as SP ACS URL (Single Sign On URL).
Audience (EntityID): copy the value from SP Entity ID (Audience URI). (number 2 in the screenshot above)
Set ACS (Consumer) URL Validator to
- Leave everything else the same and Click on Save.
Add Parameters needed by Tallyfy:
Select the Access tab from the app connector page.
You will need to add three parameters just like the screenshot below:
Click on the
+button on the top-right side of the table.
Fill the form with the correct values for each field (like the previous screenshot
Add users to your app connector:
With your app connector open, select the Access tab.
Ensure that the settings give you access to the app connector. For example, enable a role that will give you access. In this case, let’s say that the selected Default role grants access to relevant users:
- Click Save.
Configure SAML on Tallyfy:
Since you have an app Connector ready, First we will get the data needed to configure SAML on Tallyfy.
Click on the SSO tab in your app Connector page:
- We will use the values in the above page as SAML configs to integrate this app to our Tallyfy organization.
- Go back to our Tallyfy Support page where the SAML configs modal is still open, then we fill the values respectively, as shown in the screenshot below. This step is likely to be done by Tallyfy Support - so email us if you need on support (at) tallyfy (dot) com
- After successfully saving the configs, you will need to enable SAML in this organization.
- Click on the toggle button next to Add Configuration Details:
Congratulations, now Single Sign-On and User Provisioning using OneLogin will be working for this organizations' members.
How to provision new members to Tallyfy using SSO
- Go back to Tallyfy Support page and open the SAML configs modal, copy the Tallyfy login URL and share it with your users who have access to the OneLogin app Connector:
They can use this link to access Tallyfy, old users will just login, while new users will be added to your Tallyfy organization automatically.