Skip to content

Integrate OneLogin SSO

OneLogin SAML/SSO Integration

Want your team to access Tallyfy with their OneLogin credentials? You’ll set up SAML-based Single Sign-On (SSO) to handle authentication automatically. Takes about 30 minutes.

Requirements

  • OneLogin administrator account
  • Tallyfy Professional or Enterprise plan
  • SAML configuration values from Tallyfy Support

Implementation process overview

Here’s what you’ll do:

  1. Create a OneLogin SAML application connector
  2. Configure SAML settings in both systems
  3. Enable and test the SSO integration

SAML Integration Flow

This diagram shows the complete OneLogin-Tallyfy SAML setup and authentication flow.

Diagram

What to notice:

  • Configuration requires exchanging metadata between OneLogin and Tallyfy Support
  • Users access through a special SSO URL after setup is complete
  • New users are automatically provisioned on first login

Phase 1: Create OneLogin SAML application

Step 1: Access application management

  1. Sign in to your OneLogin portal

  2. Open the Administration menu

  3. Navigate to Applications > Applications

  4. Click Add App

    OneLogin setup workflow configuration screen

Step 2: Select and configure the connector

  1. Search for “SAML Test Connector”

  2. Select SAML Test Connector (Advanced)

  3. Edit the Display Name to “Tallyfy”

  4. Click Save

    OneLogin setup workflow configuration screen

Phase 2: Configure SAML settings

Step 1: Obtain Tallyfy SAML values

You’ll need Tallyfy’s default SAML values to configure OneLogin properly:

  1. Contact Tallyfy Support to access your organization’s profile

  2. Navigate to the Org Settings tab

  3. Click Add Configuration Details

  4. Locate the default SAML values section

    OneLogin setup workflow configuration screen OneLogin setup workflow configuration screen

Step 2: Configure the OneLogin connector

  1. Navigate to the Configuration tab in your OneLogin application connector.

  2. Enter the Tallyfy SP ACS URL into the ACS (Consumer) URL field.

  3. Enter the same URL into the Recipient field.

  4. Enter the Tallyfy SP Entity ID into the Audience (EntityID) field.

  5. Enter the ACS URL again into the ACS (Consumer) URL Validator field.

  6. Click Save.

    OneLogin setup workflow configuration screen

Step 3: Configure user attributes

  1. Navigate to the Parameters tab in your OneLogin application.
  2. Add the three parameters detailed below.

Add these three parameters - and don’t forget to check the Include in SAML assertion box for each one:

Parameter NameValue
EmailEmail
FirstNameFirst Name
LastNameLast Name
OneLogin setup workflow configuration screen

Here’s how to add each parameter:

  1. Click the + button in the top-right corner of the parameters table.

  2. Enter the parameter name (e.g., “Email”) and map it to the corresponding user attribute (Value field).

  3. Check the Include in SAML assertion box.

  4. Click Save.

    OneLogin setup workflow configuration screen OneLogin setup workflow configuration screen

Step 4: Assign users to the application

  1. Navigate to the Access tab in your OneLogin application

  2. Configure user access by selecting appropriate roles or users

  3. In this example, we’re using the Default role to grant access

  4. Click Save

    OneLogin setup workflow configuration screen

Phase 3: Configure Tallyfy with OneLogin information

Step 1: Obtain OneLogin SAML information

  1. Navigate to the SSO tab in your OneLogin application.

    OneLogin setup workflow configuration screen

  2. Note the SAML 2.0 Endpoint (HTTP).

  3. Note the Issuer URL.

  4. Note or download the X.509 Certificate.

Step 2: Provide information to Tallyfy Support

  1. Send the SAML 2.0 Endpoint (HTTP) to Tallyfy Support.

  2. Send the Issuer URL to Tallyfy Support.

  3. Send the X.509 Certificate to Tallyfy Support.

  4. Tallyfy Support will configure these values in your organization’s SAML settings.

    OneLogin setup workflow configuration screen

Step 3: Enable SAML authentication

Once Tallyfy Support confirms they’ve configured your SAML settings, it’s time to flip the switch:

  1. Toggle the SAML activation switch to enable SSO for your organization

    OneLogin setup workflow configuration screen

User provisioning and access

After you’ve completed the integration:

  1. Get the Tallyfy login URL from the SAML configuration modal (Tallyfy Support provides this)

  2. Share this URL with your team members who have access to the OneLogin application

    OneLogin setup workflow configuration screen

When users access Tallyfy through this URL:

  • Existing Tallyfy users get in immediately with automatic authentication
  • New users? They’re provisioned in Tallyfy on their first login (yes, it’s that simple)

Troubleshooting

Running into authentication issues? Check these common culprits:

  • Make sure the user has been assigned to the OneLogin application
  • Double-check parameter mappings are configured with exact names - even a tiny typo breaks everything
  • Verify the required attribute flags are enabled
  • Confirm users are using the SSO URL (not the regular Tallyfy login page)
  • Still stuck? Contact Tallyfy Support for help

Authentication > Integrate Okta SSO

Okta SAML/SSO integration with Tallyfy enables secure single sign-on authentication and automatic user provisioning through a collaborative 30-minute setup process that involves creating a SAML application in Okta configuring attribute mappings and working with Tallyfy Support to exchange configuration details.

Authentication > Integrate Microsoft Entra ID SSO

Microsoft Entra ID integrates with Tallyfy through a collaborative 30-minute SAML SSO setup process that requires creating an enterprise application configuring authentication settings and working with Tallyfy Support to exchange configuration details enabling automatic user authentication and account provisioning for seamless single sign-on access.

Authentication > Integrate Google Workspace

Google Workspace SAML/SSO integration with Tallyfy enables automatic user authentication through Google credentials via a three-phase collaborative setup process that involves creating a custom SAML application in Google Workspace configuring attribute mappings and working with Tallyfy Support to exchange configuration details for seamless single sign-on with automatic user provisioning.

Authentication > Integrate JumpCloud SSO

JumpCloud SAML/SSO integration connects JumpCloud with Tallyfy for automatic user authentication and account creation through a 30-minute collaborative setup process involving creating a custom SAML application configuring service provider settings and exchanging metadata with Tallyfy Support to enable seamless single sign-on authentication.