This feature is available in the following plans: | ||
| ✖ Base | ✖ Pro | ✔ Enterprise |
Impact: Before You Enable OneLogin SSO
Enabling OneLogin SSO affects all assigned users who use the Skykit application. They will need to log in with Skykit using OneLogin.
Requires an OneLogin Administrator
Completing the configuration requires an administrator.
OneLogin Setup for SP-initiated Login
Here’s a step-by-step guide to setting up your OneLogin application.
Log into your OnLogin Account.
Go to the Applications tab and click Add App.
Search for “SAML Custom Connector (Advanced).”
Set the Display Name to “Skykit Login.”
Application Configuration
Fill out the configuration fields as followed. If a field isn’t listed below, leave it as the default or empty.
RelayState: (leave empty)
Audience (EntityID): onelogin-skykit
Recipient: https://login.skykit.com/__/auth/handler
ACS URL Validator: ^https:\/\/login\.skykit\.com\/__\/auth\/handler$
Single Logout URL: (leave empty)
Login URL: https://accounts.skykit.com?saml=onelogin.[COMPANY_NAME].name
SAML Initiator: Service Provider
SAML nameID Format: email
SAML Issuer type: Specific
SAML encryption method: AES-256-CBC
SAML signature element: Response
SAML sessionNotOnOrAfter: 1440
Encrypt assertion: (uncheck)
Generate AttributeValue tag for empty values: (uncheck)
Sign SLO response: (uncheck)
Sign SLO Request: (uncheck)
Setting Up User Attributes
You need to map user information from OneLogin to Firebase. This data is included in the SAML assertion.
Click on the Parameters tab.
Create the folowing new parameters and map them to the corresponding OneLogin user fields. Make sure to check “Include in SAML assertion” for each one.
email > Email
firstName > First Name
lastName > Last Name
SSO and Certificate
Configure the SSO settings and provide the certificate.
Go to the SSO tab.
X 509 certificate: Choose Standard Strength Certificate (2048-bit).
SAML Signature Algorithm: SHA-256.
Login Hint: Check this box.
Login Connection Display: Uncheck this box.
Assumed Sign-in: Uncheck this box.
Obtaining and Uploading SAML Metadata
From the same SSO tab, you’ll need to get the Issuer URL, SAML 2.0 Endpoint (HTTP), and the SAML Metadata.
Click More Actions > SAML Metadata. This will download the metadata file.
Save the downloaded file. You’ll need to provide this information and the metadata file to the Firebase team.
Assign User to Application
To allow users to log in, you will need to add users to the application.
Navigate to the application you created.
On the left navigation, select “Users.”
Add users to Application.