Configure SAML with Okta
Updated over a week ago


We recommend reading the support article Configure SSO/SAML on first.

Okta is a publicly traded identity and access management company based in San Francisco. It provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, website web services, and devices.

You can use Okta to configure Single Sign-On for your Enterprise.


Step 1: Add Okta as IdP to

  • In your Team Admin panel, click Team Portal > Login & SSO > Custom Single Sign-On (SSO)

  • Click Add.


  • Select Okta in the list of IdP providers.


  • Click Add to start the configuration process (Step 2).

Step 2: Configure in Okta

โ€‹Log in with your Okta Administrator account and click the "Create New App" button in your Applications section


Select SAML 2.0


Add "" as name for the SAML integration


Configure like this:

  • Single Sign On URL: https://[yourcustomdomain][auth-id]

  • Audience URI (SP Entity ID): startme

  • Name ID format: EmailAddress

  • Application Username: Okta username

Attribute Statements:

  • name: user.login

  • email:


After you have configured in Okta, you can click the "Identity Provider metadata" link to download an XML file that contains. Save this file on your local machine.


Finally, make sure you assign People to this new "" application, so you will be able to test the flow once you have completed all 3 steps.

Step 3: Configure Okta in

  • In the Single Sign-On section on, click "Configure" next to the Okta IdP.

  • In the sidebar click Browse to upload the metadata file you got from Okta in step 2.


After you have uploaded this file, the following fields should be automatically filled:

  • SAML2.0 Endpoint

  • IDP Entity

  • Public Certificate


Optionally. you can change the label and the icon for the login button that will appear on your sign-in screen at https://[yourcustomdomain]

Now, you are done and ready to test the new Okta login flow!

Automatically Enroll Users in the Right Enterprise Teams

You can effortlessly assign Enterprise teams to members when they sign in through Single Sign-On (SSO), using a mapping between Okta Group ID and Team ID. Click here for more information.

Need assistance?

If you have any questions or issues, please email us at

We're here to help!

Did this answer your question?