TraitWare IdP SSO setup instructions

This article explains how to integrate TraitWare as a SAML Identity Provider (IdP) with KaseyaOne, enabling secure single sign-on (SSO) and optional automatic user provisioning.

Overview

Integrating TraitWare with KaseyaOne allows users to authenticate using TraitWare’s passwordless MFA experience and access KaseyaOne without managing separate credentials.

This integration uses SAML 2.0 and requires configuration in both TraitWare and KaseyaOne.

Supported features

Supported features of this integration include:

  • IdP-initiated SSO

  • SP-initiated SSO

  • Just-in-time user provisioning

Limitations

Review the following limitations of the TraitWare IdP SSO integration:

  • TraitWare does not send group claims in SAML assertions. Group-Based Access Control (GBAC) via IdP is not supported.

  • All access control is managed via:

  • User assignment in TraitWare

  • Roles and groups in KaseyaOne

Prerequisites

Ensure that the following requirements have been met before you set up IdP SSO:

  • You have a Master user account in KaseyaOne and an Administrator account in TraitWare.

  • TraitWare mobile authentication has been set up for your users.

  • You understand that TraitWare does not support group-based SAML claims.

Setup instructions

Run the following procedures to integrate TraitWare as a SAML Identity Provider (IdP) with KaseyaOne.

Before starting, it is recommended that you open two tabs in your browser—one for KaseyaOne and one for the TraitWare Admin Console.