Email addresses in and Tuple must match exactly. For example,
dev+tuple@company.com does not match dev@company.com. Verify your team’s email addresses before enabling SSO.Create a SAML connector
After signing in to your OneLogin account, click Applications > Applications in the top navigation bar.
In the search field, enter 
Fill in any required metadata, upload company logos, and save the new application.

SAML Test and select SAML Test Connector (Advanced) from the results.

Configure Tuple's metadata
After saving, click Configuration in the left-hand sidebar.
Fill in the following fields:Audience (EntityID)RecipientACS (Consumer) URL ValidatorACS (Consumer) URLLogin URL

Attach required parameters
Navigate to the Parameters section in the sidebar and click the plus button to add new fields.Tuple requires three fields in the SSO response: 
When adding each field, check the Include in SAML Assertion checkbox.
Repeat for 
Once all required parameters are added, the screen looks like this:
email, first_name, and last_name.

first_name and last_name.

Enable SAML in Tuple
Download your X.509 certificate. Click SSO in the sidebar and find the link to View Details:
Click Download to save the certificate file.
Return to the SSO screen and locate the Issuer URL and SAML 2.0 Endpoint (HTTP).
Navigate to the Settings tab of the team management dashboard.Under Sign-in methods, set Required Authentication Provider to SAML SSO. The Update SAML Configuration form appears:
Fill in the values with your metadata:Select the Email Domain that SAML should apply to. Only domains with confirmed team members are available.Click Save as draft. Your draft is saved as a Pending Update alongside your current sign-in method, so no one on your team is affected yet.
Click Test to verify the configuration end-to-end. Tuple signs you in through so you can confirm that authentication succeeds before the change affects anyone else on your team.Once the test succeeds, click Publish to make the configuration live. Active Tuple sessions persist, but new sign-ins are routed through .Use Edit to tweak the draft, or Discard to throw it away without publishing.



Only team owners can enable SAML. To find out who your team owner is, check your profile.



