Please follow the steps below to set up SAML Single-Sign On (SSO). If you have any questions about these steps, please contact your Wisq Agent Strategist for assistance.
Prerequisites
Before you begin, ensure you have:
- OneLogin Admin Console access
You will be provided the following by Wisq via Proton Mail:
- Relay State
Setup Steps
1: Create SAML Application
- Log in to your OneLogin Admin Console
- Navigate to Applications → Applications
- Click Add App
- Search for SAML Custom Connector (Advanced) and select it
- Enter Wisq as the Display Name
- Click Save
2: Configure SAML Settings
Click on the Configuration tab on the left menu. Enter the following values exactly as shown:
- Navigate to Manage → Single Sign On
- Select SAML for your Single Sign On method
Under Basic SAML Configuration, enter these values exactly as shown:
| Audience (Entity ID) | urn:amazon:cognito:sp:us-west-2_9ZxXL8AWd |
|---|---|
| ACS (Consumer) URL Validator | ^https:\/\/auth\.wisq\.com\/saml2\/idpresponse$ |
| ACS (Consumer) URL | https://auth.wisq.com/saml2/idpresponse |
| Recipient | https://auth.wisq.com/saml2/idpresponse |
| Relay State | < Provided by Wisq > |
| SAML nameID format: | |
| SAML initiator | Service Provider |
| SAML signature element | Assertion |
Click Save
3: Configure Attribute Parameters
Click on the Parameters tab. Add the following custom parameters. These are required for SSO to work and are case sensitive. For each parameter, click the + icon to add a new field.
Important: When adding each parameter, make sure to check the Include in SAML assertion checkbox.
| Field Name | Value (Dropdown) | Include in SAML assertion |
|---|---|---|
| ☑ Yes | ||
| given_name | First Name | ☑ Yes |
| family_name | Last Name | ☑ Yes |
If Wisq has discussed additional statement attributes, please add them here.
4: Confirmation
- Click on the SSO tab in the left menu. Copy the Issuer URL. This is your metadata URL.
- Send your point of contact, or help@wisq.com if you’re unsure, the metadata URL.
- Wisq will confirm when configuration is complete and provide instructions to test the log-in flow.