Please note: The instructions listed in this article are exclusively applicable to those who have had SAML Single Sign-On activated for their company by Aircall. To have SAML Single Sign-On activated for your company, please contact your Account Manager. Please note that, at this time, this functionality is only offered for a limited number of customers.
______________________________
Step 1: Create a SAML app integration
-
On the OneLogin portal page, choose Administration.
-
At the top of the Administration page, click on Applications, and then choose Add app.
-
In the search bar under Find Applications, enter saml, and then choose SAML Test Connector (IdP) to open the Add SAML Test Connector (IdP) page.
-
(Optional) Do any of the following:
a. For Display Name, enter a name and description. For example, acme-saml@aircall.
b. For Rectangular Icon and Square Icon, upload thumbnail icons following the specifications on the page.
c. For Description, enter a short summary description. For example, For Aircall. -
Click On Save
Step 2: Configure SAML integration for your OneLogin app
-
Click on Configuration.
-
On the Configuration page, do the following:
a. For RelayState, enter any valid URL, such as https://dashboard.aircall.io .
b. For Audience, enter urn:amazon:cognito:sp:us-west-2_hZkGBmIsz .
c. For Recipient, enter https://sso.aircall.io/saml2/idpresponse .
d. For ACS (Consumer) URL Validator, enter https://sso.aircall.io/saml2/idpresponse.
e. For ACS (Consumer) URL, enter https://sso.aircall.io/saml2/idpresponse .
f. Leave Single Logout URL blank.
g. Click on Save -
Click on Parameters.
Note: One parameter (NameID (fka Email)) is already listed—this is expected.a. Click on Add parameter to create a new, custom parameter.
b. In the New Field dialog, for Field name, enter http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier.
c. For Flags, select the Include in SAML assertion check box.
d. Choose Save.
e. For Value, choose Email from the list.
f. Click on Save.
Step 3: Assign People to your OneLogin app
1. Click on Users.
2. Search Users or select Roles/Groups.
3. Click on the Save button to either assign the app to people or user groups to enable SAML authentication for Aircall.
Step 4: Export the Metadata
1. Click on SSO.
2. Under Issuer URL, copy the URL to your clipboard.
3. Use the URL as the metadata
For more information on SAML, please read more here or contact your Account Manager.