Set up an enterprise customerPreview
Large customers want their people to sign in to your product with the company account they already use. In TrustPort, each such customer is an organization with its own domains and its own identity provider connection.
The onboarding journey
1. Create the organization
- Name it after the customer
Use the name your team would search for, like “Acme Corp”.
- Add their email domains
Enter every domain their staff sign in with, separated by commas or spaces:
acme.com, acme.co.uk. Domains are how TrustPort knows thatada@acme.combelongs to Acme, so each domain can belong to only one organization. - Pick their identity provider, if you know it
Leave it as None for now if you'll collect the details through the Admin Portal.
Supported identity providers
| Provider | Protocol |
|---|---|
| Okta | SAML 2.0 |
| Microsoft Entra ID (Azure AD) | SAML 2.0 or OIDC |
| Google Workspace | SAML 2.0 or OIDC |
| Ping Identity | SAML 2.0 |
| OneLogin | SAML 2.0 |
| Any other SAML 2.0 provider | Generic SAML 2.0 |
| Any other OpenID Connect provider | Generic OIDC |
2. Collect their identity provider details
You need different details depending on the protocol their IT team uses:
| SAML 2.0 | OpenID Connect |
|---|---|
| IdP entity ID | Issuer URL |
| IdP sign-on URL | Client ID |
| Signing certificate (PEM) | Client secret, shared with you over a secure channel |
The easiest way to get them is to let the customer's IT admin enter them directly. Send them an Admin Portal link; it takes them a few minutes and no TrustPort account.
3. Review and activate
- Check what they submittedIn the dashboardEnterprise Directory Sync›Submitted connection
Pick the organization to see the protocol, identifiers, certificate and contact email they sent.
- Switch SSO onIn the dashboardOrganizations›Edit
Set the provider and tick SSO active. TrustPort only allows this once the organization has a provider and at least one domain.
- Confirm it is ready
SSO diagnostics marks each organization Ready or lists what's missing.
Manage organizations
- Filter the list by SSO status to see which customers are still mid-setup.
- Export the list to CSV for account reviews.
- Deleting an organization frees its domains for use elsewhere.
Organizations can also be managed through the API:
curl -X POST https://id.trustportidentity.com/api/v1/organizations \
-H "Authorization: Bearer $TRUSTPORT_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "name": "Acme Corp", "domains": ["acme.com"] }'Directory Sync
Automatically creating and removing users when the customer changes them in their directory (SCIM) Coming soon is on the roadmap. Until then, invite users or create them through the API.