Skip to main content

Step 1: Get your ACS URL from Plecto

ACS URL stands for Assertion Consumer Service URL and is also referred to as the service provider sign-in URL or recipient URL. You will need to use this URL when configuring OneLogin in step 2.

  1. Go to Organization > Settings.

  2. Click the Enable SSO checkbox.

  3. Copy the URL from the ACS URL field.

  4. Proceed to OneLogin and Step 2.

Step 2: Configure OneLogin

  1. Go to onelogin.com/admin > Applications > Add app.

  2. Search for "SAML."

  3. Choose SAML Test Connector (Advanced) OneLogin, Inc. and add it.

  4. Go to Configuration and create the following setup:

Recipient

https://app.plecto.com/auth/sso/<UUID>/saml/

ACS (Consumer) URL Validator

.*

ACS (Consumer) URL

https://app.plecto.com/auth/sso/<UUID>/saml/

Login URL

https://app.plecto.com/auth/sso/<UUID>/saml/

SAML nameID format

Email

NameID Policy

Transient

SAML signature element

Both (Assertion and Response)

  1. Go to Parameters and create the following setup:

Login

Email

Include SAML assertion

First Name

First Name

Include SAML assertion

Last Name

Last Name

Include SAML assertion

  1. Save and move to Step 3.

Step 3: Configure Plecto

  1. Go to Organization > Settings.

  2. Make sure the Enable SSO option is checked.

  3. Choose With metadata file.

  4. SAML metadata URL – Use the Issuer URL from OneLogin. You can find it in OneLoginSSOIssuer URL, and it should look like the following: https://app.onelogin.com/saml/metadata/0d85...

  5. Allow SAML provisioning – If enabled, employees with access to SSO will automatically be created when trying to log in to Plecto.

  6. Click Save to finish.