Skip to main content
Last Updated: 2025-10-03
Reference: OneLogin SSO Configuration

Reference: OneLogin SSO Configuration

This topic provides additional information about configuring OneLogin as your identity provider (IdP) for Single Sign-On (SSO). For general SSO configuration steps, see Steps: Configure Single Sign-On (SSO) for Contract Management and Document Intelligence.

Considerations for OneLogin Configuration

  • Application type
    : When adding a new app in OneLogin, search for custom SAML and select
    SAML Custom Connector (Advanced)
    .
  • ACS Reply / Recipient URL
    in Contract Management and Document Intelligence is the same as the
    OneLogin ACS (Consumer) URL
    . The
    Identifier URL
    in Contract Management and Document Intelligence is the same as
    ACS (Consumer) URL Validator
    .
  • When completing the configuration in OneLogin, select:
    Option
    Description
    SAML Initiator
    Service Provider
    SAML name ID
    Transient
    SAML Issuer Type
    Specific
    SAML signature element
    Both
    SAML encryption method
    AES-256-CBC
  • Attribute mappings
    : In OneLogin, you must add and configure parameters for each attribute, such as first name, last name, and email. Select
    Include in SAML assertion
    check box for each parameter. The names you provide for these parameters are the keys, not the user's personal information, and you must use them exactly as typed in the Contract Management and Document Intelligence SSO configuration..
  • Signature algorithm
    : Ensure that the signature algorithm is set to
    SHA-256
    in both OneLogin and Workday.