This document has been generated with machine translation.
*For instructions on how to set up SSO on the LegalOn side, see “ Set up SSO (Single Sign-On).”
Terms of Use
LegalOn Terms
Okta Requirements
*If you wish to sign up for one of the Options, please contact your sales representative. |
Important Notes
SAML authentication currently supports only SP-Initiated SSO (where the Service Provider begins the SAML authentication process), which requires logging in from the LegalOn login screen each time. Please note that an error will occur during the authentication process and authentication will not be completed.
If you enable SSO while the settings are incorrect, you will be unable to log in if you close your browser or Logout. After enabling SSO, please be sure to test whether you can log in successfully by following the “Test SSO Login” procedure—either in a different browser or in incognito mode in the same browser—while keeping the SSO settings screen open.
SSO settings in the Okta Admin Console
1. Log in to Okta with an Administrator account
2. Click [Applications] → [Applications] → [Browse the App Catalog]
3. Enter "LegalOn" in the search bar and click the [LegalOn (Japan)] app
4. Click [+ Add Integration]
5. On the [General Settings] tab, copy and paste the [Endpoint URL] from LegalOn’s SSO settings into the [Endpoint URL] field, then click [Done]
Important Note
LegalOn supports only SP-initiated SSO (a method where the Service Provider begins SAML authentication).
Therefore, we recommend checking the boxes for [Do not display the application icon to Users] and [Do not display the application icon in the Okta mobile app].
6. Click the [Assignments] tab, then [Assignments], and assign the users for whom SSO is enabled
7. Open the [Sign-On] tab and click [Save] under the [Settings] section
8. Under [Credential Details], change [Application User name Format] to [Email address] and click [Save]
Okta Configuration Settings | Input Value |
Application User name Format | Email address |
9. On the [Sign-On] tab, click [Details].
10. Obtain the [Sign-On URL] and [Signing Certificate] required for LegalOn’s SSO settings, then copy and paste them into the corresponding fields in LegalOn’s SSO settings
Values to Obtain from Okta | LegalOn Configuration Fields |
Sign-On URL | Copy and paste into the [Identity provider endpoint URL (HTTP redirect)] field on the LegalOn SSO settings screen |
Signing Certificate | Method 1: Click [Download], then paste it into the [SAML signing certificate (X.509 public key certificate issued by the identity provider)] field on the LegalOn SSO settings screen * Please copy and paste All the strings, including “----BEGINCERTIFICATE-----
Method 2: Click [Copy], then paste the data formatted as shown below into the “SAML signing certificate (X.509 public key certificate issued by the identity provider)” field on the LegalOn SSO settings screen -----BEGIN CERTIFICATE----- |
Note
The following SAML attributes are supported.
Name: email
Value: user.email
This completes the Okta setup.
Once the configuration is complete, please configure SSO settings on the LegalOn side.
For instructions on how to set up SSO on the LegalOn side, see “ Set up SSO (Single Sign-On).”




