OneLogin is a single sign-on provider that Aha! connects with through our SAML 2.0 support.
Click any of the following links to skip ahead:
- Set up Aha! in OneLogin
- Set up OneLogin in Aha!
- Log into Aha! with OneLogin
- New Aha! users through SSO
Set up Aha! in OneLogin
- Create a new App by going to the Apps tab in OneLogin and selecting, "Add App."
- On the Find Applications page, search for Aha! and select it.
- Select SAML 2.0 connector, then Save.
- Configure the subdomain in the Configuration section by setting it to your Aha! subdomain.
- Go to the SSO section. Here, you will need to copy the Issuer URL so you can finish the setup process in Aha!
Set up OneLogin in Aha!
- Now that OneLogin is set up, go to Aha! and navigate to the Settings ⚙️ > Account > Security and Single Sign-On page. You will need to be an administrator with account privileges to do this. In the Single Sign-On section, select SAML 2.0 as the Identity Provider.
- Name the SSO configuration. This will be used throughout Aha! to help users identify how they are logging in.
- Configure using the Metadata URL. Fill in the Metadata URL field with the Issuer URL copied from the OneLogin SSO page and hit Enable. After the metadata is fetched from OneLogin, Aha! will switch to Manual Settings. This lets you confirm that they match the info in OneLogin.
Log into Aha! with OneLogin
- Go to your Aha! login page. Your login page will now have an additional Login with OneLogin option available.
- Clicking Login with OneLogin will send your browser to https://app.onelogin.com/login to authenticate with OneLogin. If you are already logged in, your browser will go right to Step 3 without showing you a login form.
- You are now logged into Aha!
New Aha! users through SSO
Users logging in with OneLogin are separate accounts from ones that log in with an email and password. If an email and password user exists that has a matching email address to the OneLogin user, it will be automatically converted to use OneLogin SSO. Otherwise, a new user will be automatically provisioned.
Auto-provisioned users are added with a permissions role of none for all workspaces. They also fall under the same seat restrictions as any other user. Attempts to log in may fail if you have no seats available on Premium accounts. For Enterprise accounts, the login will not fail due to seat restrictions because you can have unlimited reviewers, viewers, or none.
After a new user is added through SSO login, an Aha! administrator with account permissions will need to configure their user permissions. All SSO users will be specifically tagged for the SSO platform they are using on the administrator's Settings ⚙️ > Account > Users screen.