OneLogin secure SSO integration with SAML
OneLogin is a cloud-based identity and access management company that offers enterprise-level companies and organizations a unified access management (UAM) platform.
This document explains how to configure OneLogin and Invicti Platform for Single Sign-On.
Configure OneLogin with SAML
There are two steps to this procedure:
Step 1: Add Invicti to OneLogin
- Select Applications > Applications in the OneLogin admin's main menu.
- Click Add App.

- On the Find Applications page, search for "test connector" and select SAML Custom Connector (Advanced) from the search results.

- On the Add SAML Custom Connector (Advanced) page, enter a name for your app and optionally change icons and enter a description.
- Enable the Visible in portal toggle.

- Click Save to add the application.
Step 2: Configure OneLogin Single Sign-On Integration with SAML
- Select Applications > Applications in OneLogin.
- Click your app to edit it.
- In a new browser tab, select Settings > Security & access control > SSO & Provisioning from the Invicti left-side menu.
- Turn on the Enable SSO toggle.
- Select OneLoginSecure from the SSO Provider drop-down list.

- In the OneLogin tab, select Configuration from the left-side menu.
- In the Invicti tab, copy the SAML 2.0 Service URL and paste it into the ACS (Consumer) URL Validator field on the OneLogin tab.
- In the Invicti tab, copy the Identifier URL and paste it into the ACS (Consumer) URL field on the OneLogin tab.

- Select Save in the OneLogin tab.
- Select Parameters from the left menu in the OneLogin tab.
- Click + (the plus sign) to add a new parameter.
- On the New Field dialog, enter
user.FirstNameto the Field name.

- Select Include in SAML assertion and click Save.
- On the Edit Field
user.FirstNamedialog, select First Name from the Value drop-down. Then click Save.

- On the SAML Custom Connector (Advanced) page, select SSO.
- From the SAML Signature Algorithm drop-down, select SHA-256.
- Copy the Issuer URL field into the IdP Identifier field in Invicti.
- In the OneLogin tab, copy the SAML 2.0 Endpoint (HTTP) URL. Then paste it into the SAML 2.0 Endpoint field in Invicti.

- In the OneLogin tab, select View Details in the X.509 Certificate section.

- Copy the X.509 Certificate information and paste it into the X.509 Certificate field in Invicti.
- In Invicti, if you select Require encrypted assertions, do one of the following:
- Select Generate a new certificate; OR
- Select I have an existing certificate, then upload your certificate and enter the certificate password.

- On the OneLogin page, select Save to save the settings.
- From the Invicti SSO Exemptions drop-down, you can select specific users to exempt them from SSO. This means the selected users can log in to Invicti via password.
- Click Save on the Invicti tab to complete the integration.
Now you can add users to the Invicti application in OneLogin, and they can log in to Invicti using Single Sign-On.
info
To learn more about the Single Sign-On fields, refer to the Single Sign-On configuration document.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center
Was this page useful?