Tip
We recommend reading Configure SSO/SAML on Start.me first.
OneLogin is a cloud-based identity and access management provider. You can use it to configure Single Sign-On for your Start.me Enterprise.
Step 1: Add OneLogin as IdP to Start.me
In your Team admin panel, go to Authentication & SSO → SSO tab.
Click Add.
Select OneLogin in the list of IdP providers.
Click Add to start the configuration process (Step 2).
Step 2: Configure Start.me in OneLogin
Log in with your OneLogin Administrator account and click the "Add App" button in your Applications section. Search for SAML and select SAML Custom Connector (Advanced).
Add "Start.me" as display name.
Configure Start.me with the following data:
Metadata URL | https://[yourteamdomain].start.me/users/auth/saml2/metadata?id=[auth-id] |
ACS URL | https://[yourteamdomain].start.me/users/auth/saml2/callback?id=[auth-id] |
ACS URL Validator | https://[yourteamdomain].start.me/users/auth/saml2/callback?id=[auth-id] |
Recipient | https://[yourteamdomain].start.me/users/auth/saml2/callback?id=[auth-id] |
Audience (EntityID) | startme |
SAML initiator | OneLogin |
SAML nameID format | |
Required attributes |
|
Now click on Parameters and add the following 2 fields:
SAML Custom Connector | Value |
name | Username |
Now go back to the "Configuration" tab and use the "More actions" menu to retrieve OneLogin SAML Metadata.
Save this metadata XML file locally on your machine.
Make sure you assign People to this new "Start.me" application, so you will be able to test the flow once you have completed all 3 steps.
Step 3: Configure OneLogin in Start.me
In the SSO section on Start.me, click the three-dot menu next to the OneLogin IdP and select Change configuration.
In the sidebar click Browse to upload the metadata file you got from OneLogin in step 2.
After you've uploaded this file, the following fields should be automatically filled:
SAML2.0 Endpoint
IDP Entity
Public Certificate
Optionally, you can change the label and the icon for the login button that will appear on your sign-in screen at https://[yourcustomdomain].start.me/users/sign_in.
You are now done and ready to use the OneLogin login flow.
Automatically enroll users in the right Enterprise teams
You can automatically assign users to the correct Enterprise teams based on their group memberships. See Automatically Assign Users to Enterprise Teams via SSO for setup instructions.
Need assistance?
For questions or help with the SSO setup, please contact our team at support@start.me.
