SpaceIQ supports an integration with the OneLogin identity management system. This article will walk you through the steps required to connect SpaceIQ with OneLogin.
Upon completion of the integration steps, you'll enjoy the following capabilities:
- Pushing New Users - New users created through OneLogin will also be automatically created in the SpaceIQ application.
- Pushing Profile Updates - Updates made to users' profiles through OneLogin will be pushed to SpaceIQ.
- User Deactivation - Whenever a user is deactivated or disabled through OneLogin that user will also be deactivated in SpaceIQ. (This involves removing all of the users's data and deleting their account.)
- Download Users from Third Party Apps - New users created in the third party application will be downloaded and turned into new AppUser objects, for matching against existing SpaceIQ users.
- Logout Redirect - This redirects an end-user when the log out of SpaceIQ back to the OneLogin application where they can continue working.
It is not possible to import (or pull) new users or profile updates from within SpaceIQ. The information must be pushed from OneLogin.
Begin inside the SpaceIQ web application by clicking on your profile name in the top right corner  and selecting settings . Scroll down to see the Integrations section , where you will click on Third Party Integrations :
On the integrations page, you can either select Provisioning & SSO  then click on the Activate button under OneLogin , or you can search at the top  and select OneLogin from the search results :
On the next page you will see two tabs at the top, one for Provisioning and one for SSO. Starting with Provisioning , find and select the SCIM Bearer Token . Copy and save this token in a secure location for later use:
If you want to enable Single Sign On, under the SSO tab , you'll see additional options. Any fields that are blank will need to be populated with data from OneLogin, which we will discuss in greater detail below. Save the SAML Audience URI  for use in setting up the integration within OneLogin. The SSO Redirect URL Field  should be populated with OneLogin's SAML 2.0 Endpoint (HTTP), to take advantage of the SpaceIQ initiated SSO Login Flow. Likewise, for the Logout Redirect feature, you'll want to fill in your company's OneLogin domain URL portal , such as https://example.onelogin.com/app/portal:
Inside OneLogin, click on the Apps tab , then click on Find Apps : Search for SpaceIQ , and when you find it look for the small add link to the right :
To setup the integration with SSO, navigate to the SSO tab . Copy and paste the SAML 2.0 Endpoint (HTTP) value  back to the SpaceIQ SSO Redirect URL field. The Issuer URL  should be copied to SpaceIQ's SAML Issuer URL field. Expand the X.509 Certificate details by clicking on View Details . There you will see the certificate, which you should copy and paste as well back into the SpaceIQ X.509 Certificate field. When you are done, be sure click Activate in SpaceIQ:
Next you will need to navigate to the Configuration tab in OneLogin  and copy/paste the SCIM Bearer token from SpaceIQ into the corresponding OneLogin field . After pasting the token, click on Save in the top right corner :
- Users without a First Name or/and a Last Name in their SpaceIQ profiles cannot be imported to OneLogin as new users.
- OneLogin Users without a department will be created with a default department named “__No_Department__".
- In the event that a department also has teams or sub-departments, SpaceIQ will expect Organizations/Divisions to also contain Team/Sub-Department name.
Organization: Engineering, with Department: QA