Skip to content

OneLogin SSO

Add a OneLogin SAML 2.0 app with the Avaloi details and paste its metadata URL into Avaloi.

Connect OneLogin to Avaloi with SAML 2.0. Only the Owner can save the connection, and it is for Enterprise accounts. The full flow, including domain proof, testing, and mandatory sign-on, is in Single sign-on with SAML.

Connect OneLogin

  1. Add a SAML app. In OneLogin, add a SAML Custom Connector (Advanced).
  2. Add the Avaloi details. Set Audience (EntityID) to the Entity ID, and ACS (Consumer) URL and ACS URL Validator to the ACS URL, from the Single sign-on page in Avaloi.
  3. Set the SAML signature element to Assertion or Both, and the SAML nameID format to Email. Map Email to the NameID.
  4. Copy the Issuer URL (the metadata address) from the app's SSO tab.
  5. In Avaloi, open Company settings, then Single sign-on, then Enable. Paste the metadata URL, list your email domains, and save.
  6. Add the DNS TXT record Avaloi shows under Domain proof, choose Verify domain, then choose Test connection.
  7. Sign in once through Sign in with your company. When that works, turn on Mandatory single sign-on if you want it.

Quick answers

The first sign-in created a user with no name. Add first name and last name to the SAML attributes in OneLogin. Avaloi fills them in at the next sign-in.

Avaloi refused the response. Check that the assertion is signed, that the email is the NameID or the email attribute, and that the email is on a domain you verified. See the fixes in Single sign-on with SAML.

Members are stuck in a loop. The Owner can always sign in with a password. Turn Mandatory single sign-on off, fix the connection, run Test connection, then turn it on again.

API

  • GET /v1/companies/me/sso/sp-metadata
  • PUT /v1/companies/me/sso
  • POST /v1/companies/me/sso/test

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.