This article explains setting up your OneLogin SSO provider with Expel Workbench

  1. Log into your OneLogin Console and navigate to Administration in the top right corner.

  2. Navigate to Applications > Add App.

  3. Search for SAML and select SAML Test Connector (IdP w/attr w/ sign response).

  4. Under Portal:

    • Display Name: Expel Workbench.

  5. Select Configuration in the left navigation.

  6. Copy information from Expel Workbench to complete the integration. Open a new tab or window and log in to Expel Workbench (https://workbench.expel.io).

  7. Navigate to Organization Settings > My Organizations and select the organization. Then click Integrations > Configure SSO.

  8. Copy and paste the following from Expel Workbench into OneLogin.

    • ACS URL or Single Sign-on URL → ACS (Consumer) URL.

    • Audience URI or Audience → Audience.

    • ACS URI Validator → ACS (Consumer) URI Validator.

    • Leave Yes, allow users to log in locally OR via SSO selected for local logins. This makes initial SSO setup easier. You can change this later.

  9. In Expel Workbench, click Next.

    • Select Parameters from the left navigation.

    • Click the “+” button on the left to add a new parameter.

    • For Field name type the word email and select Include SAML assertion. Click Save.

  10. In OneLogin, click Save in the upper right corner.

    • For Value, select Email from the list and click Save.

  11. Navigate to SSO in the left navigation.

  12. Right-click and open in a new tab or window View Details under the X.509 Certificate.

  13. Copy and paste the X.509 Certificate from OneLogin into Expel Workbench.

  14. Back in the SSO window, copy and paste the following from OneLogin into Expel Workbench.

    • SAML 2.0 Endpoint (HTTP)→ Single Sign-On URL or SAML 2.0 Endpoint.

    • Issuer URL → Issuer or Issuer ID.

  15. Click Save in Expel Workbench.

  16. Click Save in OneLogin.