Knowledge base SSO & provisioning
Connect Okta with SAML
Before you start, open Settings → Organization here in another tab, choose SAML under Single sign-on, and save the connection — that reveals the SP entity ID and ACS URL you'll paste into Okta.
- In Okta Admin, create an app integration and choose SAML 2.0.
- Paste our ACS URL into Okta's "Single sign-on URL" and our SP entity ID into "Audience URI (SP Entity ID)".
- Set the Name ID format to EmailAddress and the application username to email. We match people by email address, so this mapping is the one that matters.
- Finish creating the app, then open View SAML setup instructions. Copy Okta's Identity Provider Issuer into our IdP entity ID field, the Identity Provider Single Sign-On URL into our IdP single sign-on URL field, and the X.509 certificate into our certificate field.
- Assign the app to your people in Okta, save the connection here, run the test, and enable it.
From then on, staff can start from the Okta tile or from our SSO page with their work email — both paths end at your Okta sign-in. First-time users are added to your organization automatically, seats permitting.
Okta can also manage the roster itself, creating accounts on hire and deactivating them on departure — that's a separate provisioning setup covered in SCIM for Okta.