Single Sign On Set Up - OneLogin

Written By rosa.elliscook (Administrator)

Updated at November 19th, 2025

This article will provide the steps required to set up Nomos One single sign on access for your organisation, using OneLogin as the identity provider.


App Creation

  1. Sign in to the OneLogin portal.
  2. At the top of the page, click “Applications”.
  3. Click the “Add App” button.
  4. On the “Find Applications” page, search for “SAML Custom Connector (Advanced)” and click on the application that appears below.
  5. Enter the name of your app. This can be updated later if need be. 
  6. Click “Save”.
  7. Once the page reloads, click on “Configuration”. 

At this point you should have an app created, and land on a page that looks similar to this:

Single Sign On setup

  1. Staying within the page you just generated, update the form to match the following:
    1. For “RelayState”, leave blank.
    2. For “Audience (EntityID)”, enter: urn:amazon:cognito:sp:<USER_POOL_ID>
    3. For “Recipient”, enter: https://onelease-<dev|stg|prod>.auth.ap-southeast-2.amazoncognito.com/saml2/idpresponse
    4. For “ACS (Consumer) URL Validator”, enter a regular expression used to ensure that OneLogin posts the SAML response to the correct URL by validating the “ACS (Consumer) URL” entered in the next field. For more information on this step, please refer to this article in the OneLogin knowledge base.
    5. For “ACS (Consumer) URL”, enter": https://onelease-<dev|stg|prod>.auth.ap-southeast-2.amazoncognito.com/saml2/idpresponse
    6. For “Single Logout URL”, leave blank.
    7. For “Login URL”, leave blank.
    8. For “SAML not valid before”, enter: 3
    9. For “SAML not valid on or after”, enter: 3
    10. For “SAML initiator”, enter: “Service Provider”
    11. For “SAML nameID format”, enter: “Persistant”
    12. For “SAML issuer type”, enter: “Specific”
    13. For “SAML signature element”, choose both.
    14. For “Encryption assertion”, check the box.
    15. For “SAML encryption method”, enter: “AES-256-CBC”.
    16. For “Send NameID Format in SLO Request”, check the box.
    17. For “Generate AttributeValue tag for empty values”, check the box.
    18. For “Sign SLO Request”, un-check the box.
    19. For “Sign SLO Response”, un-check the box.
    20. For “SAML sessionNotOnOrAfter”, enter: 1440
  2. Click the “Save” button.
  3. Click on “Parameters".
  4. Click the + icon to add a new field for the required SAML assertion:
    1. In the “Name” field, enter: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    2. Check the box for “Include in SAML assertion” and click “Save”.
    3. Once the model refreshes, change the “Value” drop-down to “Email”. Click “Save”.

The majority of the setup within OneLogin is now done. The certificate conversion still needs to be done, but will be processed after the Cognito configuration, which is handled by the Nomos One team.

Certificates

  1. In Cognito, go to the IdP page for the provider created in the previous step.
  2. Click “View encryption certificate”.
  3. Click “Copy”.
  4. We now need to format the certificate before entering into OneLogin:
    1. Navigate to this OneLogin page: https://developers.onelogin.com/saml/online-tools/x509-certs/format-x509-certificate
    2. Enter the certificate that you copied into the “X.509 cert” field, and click “FORMAT X.509 CERTIFICATE”.
    3. Copy the certificate from the “X.509 cert with header” text box.
  5. Return to the OneLogin application.
  6. Click on “Configuration” and scroll to the bottom of the page.
  7. Enter the copied certificate into the text field under “SAML Encryption”.
  8. Click “Save”.

The setup process will now be complete, and your organisation can begin using single sign on to access Nomos One.


Nomos One does not provide or purport to provide any accounting, financial, tax, legal or any professional advice, nor does Nomos One purport to offer a financial product or service. Nomos One is not responsible or liable for any claim, loss, damage, costs or expenses resulting from your use of or reliance on these resource materials. It is your responsibility to obtain accounting, financial, legal and taxation advice to ensure your use of the Nomos One system meets your individual requirements.