TrustPortDocs
What’s in preview
You can create organizations, claim domains and collect your customers' SAML and OIDC details today. Routing their users through their identity provider at sign-in is rolling out now; organizations you set up will start using it without any changes on your side.

The onboarding journey

1Create the organizationName and email domains
2Collect IdP detailsYou, or their IT admin via the Admin Portal
3ReviewCheck what was submitted
4ActivateSwitch SSO on for the organization
5VerifyConfirm readiness in diagnostics

1. Create the organization

In the dashboardOrganizations›Create organization
  1. Name it after the customer

    Use the name your team would search for, like “Acme Corp”.

  2. Add their email domains

    Enter every domain their staff sign in with, separated by commas or spaces: acme.com, acme.co.uk. Domains are how TrustPort knows that ada@acme.com belongs to Acme, so each domain can belong to only one organization.

  3. Pick their identity provider, if you know it

    Leave it as None for now if you'll collect the details through the Admin Portal.

Supported identity providers

ProviderProtocol
OktaSAML 2.0
Microsoft Entra ID (Azure AD)SAML 2.0 or OIDC
Google WorkspaceSAML 2.0 or OIDC
Ping IdentitySAML 2.0
OneLoginSAML 2.0
Any other SAML 2.0 providerGeneric SAML 2.0
Any other OpenID Connect providerGeneric OIDC

2. Collect their identity provider details

You need different details depending on the protocol their IT team uses:

SAML 2.0OpenID Connect
IdP entity IDIssuer URL
IdP sign-on URLClient ID
Signing certificate (PEM)Client secret, shared with you over a secure channel

The easiest way to get them is to let the customer's IT admin enter them directly. Send them an Admin Portal link; it takes them a few minutes and no TrustPort account.

3. Review and activate

  1. Check what they submitted
    In the dashboardEnterprise Directory Sync›Submitted connection

    Pick the organization to see the protocol, identifiers, certificate and contact email they sent.

  2. Switch SSO on
    In the dashboardOrganizations›Edit

    Set the provider and tick SSO active. TrustPort only allows this once the organization has a provider and at least one domain.

  3. Confirm it is ready

    SSO diagnostics marks each organization Ready or lists what's missing.

Manage organizations

  • Filter the list by SSO status to see which customers are still mid-setup.
  • Export the list to CSV for account reviews.
  • Deleting an organization frees its domains for use elsewhere.

Organizations can also be managed through the API:

Create an organization
curl -X POST https://id.trustportidentity.com/api/v1/organizations \
  -H "Authorization: Bearer $TRUSTPORT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "name": "Acme Corp", "domains": ["acme.com"] }'

Directory Sync

Automatically creating and removing users when the customer changes them in their directory (SCIM) Coming soon is on the roadmap. Until then, invite users or create them through the API.

© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.