Explore documentation
OneLogin SSO
In this guide, you're going to learn how to connect OneLogin with Better Stack to enable single sign-on (SSO) for you and your colleagues.
- Start the SSO set-up by going to Single Sign-On configuration. Note that only organization admins have access to these settings. 
- On this page click Connect on the Generic SAML SSO panel. 
- Select OneLogin from the list of supported providers. 
- Take note of the values in the Entity ID and ACS URL fields, we're going to need these in a second. 
We're going to switch to OneLogin now:
- Visit the OneLogin Administration panel, at the URL - https://<your-tenant>.onelogin.com/admin2
- In the top menu, click on Applications, then select Applications from the dropdown menu. 
- Click on Add App. 
- In the search box enter "SAML custom connector", then select "SAML Custom Connector (Advanced)" from the results. 
- Under Display Name, enter Better Stack, then click Save. 
- In the navigation menu on the left select Configuration. 
- Fill in Audience (EntityID) paste the Entity ID copied from Better Stack above. 
- Fill in Recipient with the ACS URL copied from Better Stack above. 
- Fill in ACS (Consumer) URL Validator with - ^https:\/\/betterstack.com\/users\/auth\/saml\/.*
- Fill in ACS (Consumer) URL with the ACS URL copied from Better Stack above. 
- Under SAML encryption method select AES-256-CBC 
- Click Save at the top right, to apply the changes. 
- In the navigation menu on the left select Parameters. 
- Click on the + icon. 
- Fill in Field name with email, check the Include in SAML assertion box, then click Save. 
- From the Value dropdown select Email, then click Save again. 
- Click the + icon again. 
- Fill in Field name with first_name, check the Include in SAML assertion box, then click Save. 
- From the Value dropdown select First Name, then click Save again. 
- Click the + icon one final time. 
- Fill in Field name with last_name, check the Include in SAML assertion box, then click Save. 
- From the Value dropdown select Last Name, then click Save again. 
- In the navigation menu on the left select SSO. 
- Copy the Issuer URL and SAML 2.0 Endpoint (HTTP) URL. We'll need these in a moment. 
- Under X.509 Certificate click View Details, then Download the displayed certificate. We'll need this in a moment as well. 
We'll switch to Better Stack now:
- Visit the "Single Sign On" page https://betterstack.com/settings/sso 
- Under Generic SAML SSO, click Connect. 
- Under Provider, select OneLogin. 
- Under Identity Provider Single Sign-On URL enter the SAML 2.0 Endpoint (HTTP) URL copied above. 
- Under Issuer URL enter the Issuer URL copied from above. 
- Click Upload and select the Certificate file chosen above. 
- Click Connect to confirm the configuration. You will be redirected to OneLogin. Sign in with the account you assigned to the Better Stack application, please. 
Tada! Your OneLogin Single Sign-On is now configured!