Configure SAML with Okta
Updated over a week ago

Tip

We recommend reading the support article Configure SSO/SAML on Start.me first.

Okta is a publicly traded identity and access management company based in San Francisco. It provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, website web services, and devices.

You can use Okta to configure Single Sign-On for your Start.me Enterprise.

okta7.png

Step 1: Add Okta as IdP to Start.me

  • In your Team Admin panel, click Team Portal > Login & SSO > Custom Single Sign-On (SSO)

  • Click Add.

    SSO__1_.png

  • Select Okta in the list of IdP providers.
    โ€‹

    Okta.PNG

  • Click Add to start the configuration process (Step 2).



Step 2: Configure Start.me in Okta


โ€‹Log in with your Okta Administrator account and click the "Create New App" button in your Applications section

okta1.png

Select SAML 2.0

okta2.png

Add "Start.me" as name for the SAML integration

okta3.png

Configure Start.me like this:

  • Single Sign On URL: https://[yourcustomdomain].start.me/users/auth/saml2/callback?id=[auth-id]

  • Audience URI (SP Entity ID): startme

  • Name ID format: EmailAddress

  • Application Username: Okta username


Attribute Statements:

  • name: user.login

  • email: user.email

okta4.png


After you have configured Start.me in Okta, you can click the "Identity Provider metadata" link to download an XML file that contains. Save this file on your local machine.

okta5.png

Finally, make sure you assign People to this new "Start.me" application, so you will be able to test the flow once you have completed all 3 steps.



Step 3: Configure Okta in Start.me

  • In the Single Sign-On section on Start.me, click "Configure" next to the Okta IdP.

  • In the sidebar click Browse to upload the metadata file you got from Okta in step 2.

okta6a.png

After you have uploaded this file, the following fields should be automatically filled:

  • SAML2.0 Endpoint

  • IDP Entity

  • Public Certificate

okta6.png

Optionally. you can change the label and the icon for the login button that will appear on your sign-in screen at https://[yourcustomdomain].start.me/users/sign_in

Now, you are done and ready to test the new Okta login flow!


Automatically Enroll Users in the Right Enterprise Teams

You can effortlessly assign Enterprise teams to members when they sign in through Single Sign-On (SSO), using a mapping between Okta Group ID and Start.me Team ID. Click here for more information.

Need assistance?

If you have any questions or issues, please email us at support@start.me.

We're here to help!

Did this answer your question?