How to set up SSO with Okta
Written By Mikko Karjalainen
Last updated 8 days ago
Overview
Operating supports SSO with Okta as the identify provider. At a high level, the integration work like this:
After setting up Operating to use Okta as SSO, access control is handled on Okta side. If a user is allowed to access Operating in Okta application, they will be able to log in to Operating.
User accounts to Operating are provisioned just-in-time when a user logs in through the SSO connection.
New users will be given the default permission set configured in
If a Person exists in Operating with the same email as the new users, we will associate the newly logged-in users to that Person.
Users lose access to Operating after their assignment to the Okta application has been removed.
Contact us at support@operating.app if you want to set up Okta SSO for your tenant.
Setup instructions
Step 1: Create an OIDC application in Okta
Okta’s own instructions for this: https://help.okta.com/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_OIDC.htm
Select OIDC as the sign in method
Application type: Web application
Configuration
Name: Up to you, e.g. Operating
Sign-in redirect URIs: https://auth.operating.app/login/callback
Trusted origins: https://operating.app
Assignments: Define whether everyone in your organization is allowed to log in to Operating, or limit it to specific groups
Record the client ID and client secret for the app you created
Step 2: Contact us at support@operating.app
After you have created the application, contact us at support@operating.app to organise a safe delivery of the client secret and other information.
You will need to provide us with the following:
Client ID
Client secret
Your Okta domain name
See https://developer.okta.com/docs/guides/find-your-domain/main/ for instructions on finding the domain
After you have provided this information, we will configure the SSO connection on our side.
Step 3: Assign users to the application
Assign users to the application to grant them access to Operating. They are able to log in automatically after that and their users are provisioned in Operating when they log in. Users provisioned this way are granted the default permission set which can be defined here: https://use.operating.app/settings/permissions
Was this helpful?
More in SSO & provisioning
How does single sign-on (SSO) work in Operating?How to set up SSO with Entra IDStill need help? Ask the team