SSO is an Enterprise feature. Sign-in is SP-initiated (start at Planasonix). See SSO.
Planasonix values
From Settings → SSO, copy:- ACS URL (Recipient / Consumer URL in OneLogin terminology)
- Entity ID (Issuer / Audience for the service provider)
Create the SAML connector
1
Add a new application
In the OneLogin admin portal, go to Applications → Applications → Add App. Search for SAML Test Connector (Advanced) or a Generic SAML template your organization standardizes on, then add it.
2
Rename and assign
Set the display name to
Planasonix (or your standard). Optionally upload a logo. Save the application shell before detailed SAML configuration.3
Configure SAML parameters
Open the app → Configuration (or SSO depending on template). Set:
- ACS (Consumer) URL: Planasonix ACS URL
- Audience (EntityID): Planasonix Entity ID
- Recipient and Consumer URL fields, if separate: match ACS URL unless OneLogin documentation for your template says otherwise
4
Signer and algorithm settings
Under SSO or Credentials, choose SAML Signature Element (assertion, response, or both) per your security policy. Use SHA-256 for signatures unless an older integration explicitly requires SHA-1.
Parameter configuration
OneLogin exposes Parameters that map user fields to SAML assertion attributes.- Standard user fields
- Groups and roles
Enable Include in SAML assertion for each parameter Planasonix lists as required.
Template field names differ between SAML Test Connector versions. If a field is missing, check the SSO tab and Parameters tab together; some ACS settings live only under Configuration.
SSO and issuer URLs for Planasonix
Under More Actions → SAML Metadata, download metadata XML for Planasonix. Alternatively, copy:- SAML 2.0 Endpoint (HTTP) — SSO URL for manual entry
- Issuer URL — entity ID for the IdP
- X.509 Certificate — signing cert
Certificate rotation
When you renew the OneLogin signing certificate, download fresh metadata and update Planasonix before the previous certificate expires. Run a pilot login from Planasonix after upload.Related topics
SSO overview
Enforcing SSO and handling JIT provisioning.
Session policy
Session length and IP constraints after OneLogin login.