Skip to main content

Configure SAML with Okta

Step-by-step guide to set up SAML SSO with Okta.

Tip

We recommend reading Configure SSO/SAML on Start.me first.

Okta is a cloud-based identity and access management provider. You can use Okta to configure Single Sign-On for your Start.me Enterprise.

okta7.png

Step 1: Add Okta as IdP to Start.me

  • In your Team admin panel, go to Authentication & SSOSSO tab.

  • Click Add.

    SSO__1_.png

  • Select Okta in the list of IdP providers.

    Okta.PNG

  • Click Add to start the configuration process (Step 2).

Step 2: Configure Start.me in Okta

Log in with your Okta Administrator account and click the "Create New App" button in your Applications section.

okta1.png

Select SAML 2.0.

okta2.png

Add "Start.me" as name for the SAML integration.

okta3.png

Configure Start.me with the following settings:

  • Single Sign On URL: https://[yourcustomdomain].start.me/users/auth/saml2/callback?id=[auth-id]

  • Audience URI (SP Entity ID): startme

  • Name ID format: EmailAddress

  • Application Username: Okta username

Attribute Statements:

  • name: user.login

  • email: user.email

okta4.png

After you have configured Start.me in Okta, click the "Identity Provider metadata" link to download an XML file. Save this file on your local machine.

okta5.png

Finally, make sure you assign People to this new "Start.me" application, so you will be able to test the flow once you have completed all 3 steps.

Step 3: Configure Okta in Start.me

  • In the SSO section on Start.me, click the three-dot menu next to the Okta IdP and select Change configuration.

  • In the sidebar click Browse to upload the metadata file you got from Okta in step 2.

okta6a.png

After you have uploaded this file, the following fields should be automatically filled:

  • SAML2.0 Endpoint

  • IDP Entity

  • Public Certificate

okta6.png

Optionally, you can change the label and the icon for the login button that will appear on your sign-in screen at https://[yourcustomdomain].start.me/users/sign_in.

You are now done and ready to test the new Okta login flow!

Automatically enroll users in the right Enterprise teams

You can automatically assign users to the correct Enterprise teams based on their group memberships in Okta. See Automatically Assign Users to Enterprise Teams via SSO for setup instructions.

Need assistance?

If you have any questions or issues, please email us at support@start.me. We're here to help!

Did this answer your question?