Explore documentation
OneLogin SSO
Learn how to connect OneLogin with Better Stack to enable single sign-on (SSO) for you and your colleagues.
SSO setup
- Go to Single Sign-On configuration.
- Click Connect on the Generic SAML SSO panel and select OneLogin.
- Note the Entity ID and ACS URL. You will need them in a moment.
In OneLogin
- Go to the OneLogin Administration panel at
https://<your-tenant>.onelogin.com/admin2. - Go to Applications → Applications and click Add App.
- Search for "SAML custom connector" and select SAML Custom Connector (Advanced).
- For Display Name, enter
Better Stackand click Save. - In the left menu, select Configuration.
- For Audience (EntityID), use the Entity ID from Better Stack.
- For Recipient and ACS (Consumer) URL, use the ACS URL from Better Stack.
- For ACS (Consumer) URL Validator, enter
^https:\/\/betterstack.com\/users\/auth\/saml\/.*. - For SAML encryption method, select AES-256-CBC.
- Click Save.
- In the left menu, select Parameters.
- Add the following parameters, ensuring Include in SAML assertion is checked for each:
-
emailmapped to Email. -
first_namemapped to First Name. -
last_namemapped to Last Name.
-
- In the left menu, select SSO.
- Copy the Issuer URL and SAML 2.0 Endpoint (HTTP) URL.
- Under X.509 Certificate, click View Details and Download the certificate.
In Better Stack
- Go back to the SSO configuration page.
- For Identity Provider Single Sign-On URL, use the SAML 2.0 Endpoint (HTTP) from OneLogin.
- For Issuer URL, use the Issuer URL from OneLogin.
- Upload the certificate file you downloaded from OneLogin.
- Click Connect. You will be redirected to OneLogin to sign in.
You're done. Your OneLogin Single Sign-On is now configured.