Skip to main content
SSO & provisioning

How to set up SSO with Okta

Written By Mikko Karjalainen

Last updated 8 days ago

Overview

Operating supports SSO with Okta as the identify provider. At a high level, the integration work like this:

  1. After setting up Operating to use Okta as SSO, access control is handled on Okta side. If a user is allowed to access Operating in Okta application, they will be able to log in to Operating.

  2. User accounts to Operating are provisioned just-in-time when a user logs in through the SSO connection.

    1. New users will be given the default permission set configured in

      https://use.operating.app/settings/permissions

    2. If a Person exists in Operating with the same email as the new users, we will associate the newly logged-in users to that Person.

  3. Users lose access to Operating after their assignment to the Okta application has been removed.

Contact us at support@operating.app if you want to set up Okta SSO for your tenant.

Setup instructions

Step 1: Create an OIDC application in Okta

Okta’s own instructions for this: https://help.okta.com/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_OIDC.htm

  1. Select OIDC as the sign in method

  2. Application type: Web application

  3. Configuration

    1. Name: Up to you, e.g. Operating

    2. Sign-in redirect URIs: https://auth.operating.app/login/callback

    3. Trusted origins: https://operating.app

    4. Assignments: Define whether everyone in your organization is allowed to log in to Operating, or limit it to specific groups

  4. Record the client ID and client secret for the app you created

Step 2: Contact us at support@operating.app

After you have created the application, contact us at support@operating.app to organise a safe delivery of the client secret and other information.

You will need to provide us with the following:

  1. Client ID

  2. Client secret

  3. Your Okta domain name

    1. See https://developer.okta.com/docs/guides/find-your-domain/main/ for instructions on finding the domain

After you have provided this information, we will configure the SSO connection on our side.

Step 3: Assign users to the application

Assign users to the application to grant them access to Operating. They are able to log in automatically after that and their users are provisioned in Operating when they log in. Users provisioned this way are granted the default permission set which can be defined here: https://use.operating.app/settings/permissions