Configure and Provision OneLogin SAML SSO for your Organization

If you're using OneLogin, then you can configure your Figma Organization to allow users to login to their account using their OneLogin credentials.

This also allows you to control who has access to your Figma account, and manage your user accounts in one place, directly in OneLogin.

When you request a CSV of your Organizations member list while using OneLogin, some additional fields will be available including: Job Title, Cost Center Code, Division, Department, Organization, Employee Number, and Manager. To learn more about how to request a CSV member list, check out our article on Managing Organization Members.

In this article, we'll take you through the steps required to get SAML SSO set up with OneLogin:

  1. Add the Figma App to OneLogin
  2. Enable OneLogin in Figma
  3. Configure the OneLogin Application

Learn more about SAML SSO in our Getting Started with SAML SSO article.

Add the Figma App to OneLogin

First, you'll need to add the Figma App to your OneLogin account.

  1. Log in to your OneLogin account.
  2. Go to the Administration section.
  3. Go to the Apps page and select Add Apps.
  4. Search for "Figma" in the Find apps field.
  5. On the Info tab, click Save to add the app to your Company Apps.
  6. You will then be able to access the additional configuration settings. Go to the SSO tab:
  7. Copy the contents of the Issuer URL field: 

Enable OneLogin in Figma

Next, you will need to set up the OneLogin integration in Figma.

  1. Open the Admin Console in your Figma Organization:
  2. From the General page, find the Sign in and Provisioning section. Click the Update Sign in Settings link: 
  3. From the Authentication and Provisioning page, you can set your Authentication preference. Before you can select SAML SSO from the options, you will need to Configure SAML. Click the Configure SAML button at the bottom of the SAML SSO section:
  4. In the Configure SAML SSO modal, select OneLogin from the Identity Provider(Idp) section.
  5. In the IdP Metadata URL field, enter your Issuer URL from OneLogin. Click Review
  6. You'll be prompted to review and confirm the details are correct. This is the only time you will be able to make changes to your OneLogin details, without having to contact customer support. Check the box to confirm This information is correct...
  7. Click Configure SAML SSO to complete the setup process
  8. You will now see a confirmation of your OneLogin SAML SSO Configuration in the SAML SSO section. Click the Copy link next to your Tenant ID. You will need this during the set up process in OneLogin: 

Note: If you plan to use SCIM with OneLogin, you’ll also want to click Generate API token at the bottom of this page and save this token for configuration in OneLogin.

Configure the OneLogin Application

Once you've received your confirmation and Tenant ID, you can complete the configuration process in OneLogin.
  1. Go back to the Figma App in OneLogin (Administration > Apps > Figma)
  2. Go to the Configuration Tab for the Figma app:
  3. Enter the Tenant ID that you copied from Figma.
  4. Click SAVE complete the process. 

Configure SCIM 

If you would like to configure SCIM, you will need to generate an API Token in Figma. 

  1. Open the Figma app in OneLogin.
  2. Go to the Configuration Tab for the Figma app. 
  3. Under API connection, enter your API token in the SCIM Bearer Token field. 
  4. Click ENABLE to complete the process. 

Enable Provisioning

  1. Open the Figma app in OneLogin.
  2. Go to the Provisioning tab in the Figma app.
  3. Check the box next to Enable Provisioning
  4. Select which provisioning actions you want to require administrator approval for. You can choose to enable this for:
    1. Create User
    2. Delete User
    3. Update User
  5. Decide the appropriate action for When user accounts are suspended in OneLogin..

Adding Custom Attributes

Some Figma attributes are mapped to OneLogin attributes by default. You won't need to re-configure these:

  • Email
  • First Name
  • Last Name
  • NameID
  • SCIM Username
  • Title
  • Manager
  • Department

Other SCIM Enterprise User attributes are optional. You will need to add these as custom user fields if you want to include them in your provisioning:

Name Short Name
employeeNumber employeeNumber
costCenter costCenter  
organization organization  
division division

Adding Custom User Fields

To create a Custom Field in OneLogin:

  1. Login to your OneLogin account.
  2. Go to Users > Custom User Fields in the main menu: 
  3. Complete the New User Field inputs.

  4. Click SAVE to apply your changes.
Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.