Introduction
Setting up SSO lets your team access TrustLayer with your existing Identity Provider (IDP). Here’s what you’ll need to do and the information you need to provide.
Step 1: Confirm Your IDP & Protocol
TrustLayer supports these IDPs and protocols:
OIDC: Okta, Microsoft, Google, Apple
SAML: Okta, Microsoft, Google
Step 2: Gather Required Information from Your IDP
Please provide TrustLayer with the following, based on your setup:
OIDC Setup
Client ID: Obtain from your IDP.
Issuer (URL): From your IDP.
Grant Type: Set to “Implicit Flow (id_token).”Authorization Callback URL:
https://auth.trustlayer.io/__/auth/handler
SAML Setup
Entity ID: Set to trustlayer.io on your IDP.
SSO URL: Obtain from your IDP.
X.509 Certificate: Download from your IDP.
Authorization Callback URL:
https://auth.trustlayer.io/__/auth/handler
Make sure to list the domains (e.g., @yourcompany.com) you want to associate with SSO.
Step 3: Submit Your Information to TrustLayer
Once you have the required details, please send the following to TrustLayer:
For OIDC:
Client ID
Issuer (URL)
Your domains
For SAML:
Entity ID
SSO URL
X.509 Certificate (Base64)
Your domains
Step 4: TrustLayer Activation
Once we have your details, TrustLayer will activate SSO for your organization. Let us know when we can align on a time that works best for your team. After activation, all users in the specified domains will log in through your IDP.
