Single Sign-on Configuration for mfloow and OneLogin
This article outlines the steps for setting up single sign-on (SSO) for mfloow and OneLogin.
Updated June 19, 2024
Important Considerations for Usage
- To use the SSO feature, a “Business” plan or higher is required.
- Currently, only SP-Initiated SSO is supported.
- Only users with the “Owner” or “Standard Admin” role can configure SSO.
- The administrator’s email address registered in mfloow must match the email address registered in OneLogin.
- Even if SSO is enabled, members who have already set a password can continue to log in using their email address and password.
- If a member using SSO has not yet set a password in mfloow, they can do so by selecting “Reset Password.”
- To log in using SSO, users must be assigned to the mfloow app within OneLogin.
mfloow (SP) and OneLogin (IdP): Steps to Configure SSO Authentication
1. Log in to the OneLogin admin console and select “Applications” > “Add App” from the menu.
2. On the “Find Applications” screen, select “SAML Custom Connector (Advanced).”
3. On the app creation screen, enter “mfloow” as the Display Name and click the “Save” button.
4. On the next screen, click “Configuration” in the menu, enter the information below, and then click “Save.”
mfloow | OneLogin |
SP Entity ID | Audience (EntityID) |
ACS URL | Recipient |
ACS URL | ACS (Consumer) URL Validator |
ACS URL | ACS (Consumer) URL |
5. In the OneLogin mfloow app details menu, click “SSO.” In a separate window, navigate to “Settings” > “Single Sign-On” in mfloow. Next to “SAML SSO Settings” in mfloow, click the “Settings” button and enter the following information from OneLogin.
OneLogin:
mfloow:
OneLogin | mfloow |
Issuer URL | Entity ID |
SAML 2.0 Endpoint (HTTP) | SSO URL |
In the OneLogin app’s “SSO” screen, click “View Details” under “X.509 Certificate.”
Copy the displayed “X.509 Certificate” data and paste it into the “SAML SSO Settings” section in mfloow.
OneLogin:
mfloow:
Click the “Save” button to apply the SSO settings.
9. On the mfloow SSO settings screen, click the toggle for “Enable SAML SSO.”
10. In the popup, click the “Enable” button to complete the process.
How to log in using OneLogin SSO
1. On the login screen, enter your Company ID and click the “Next” button.
2. On the next screen, click the “Log in with SAML SSO” button.
If you are already signed in to OneLogin:
A popup will appear and, once the process is complete, it will close automatically and you will be logged in to mfloow.
If you are not signed in to OneLogin:
A popup will appear prompting you to enter your OneLogin credentials. After you sign in, the popup will close and you will be logged in to your mfloow account.
If you want to disable Single Sign-On (SSO)
On the mfloow SSO settings page, toggle off “Enable SAML SSO.”
A confirmation popup will appear; click the “Disable” button to turn off SSO.