Okta SSO
Create an Okta SAML 2.0 app with the Avaloi details, then paste its metadata URL into Avaloi.
Connect Okta to Avaloi with SAML 2.0. Only the Owner can save the connection, and it is for Enterprise accounts. The full flow, including domain proof, testing, and mandatory sign-on, is in Single sign-on with SAML.
Connect Okta
- Create the app. In Okta, add a SAML 2.0 app integration. Assign the groups who should reach Avaloi.
- Add the Avaloi details. Set the Single sign-on URL to the ACS URL and the Audience URI to the Entity ID, both from the Single sign-on page in Avaloi. Set Name ID format to EmailAddress and Application username to Email. Set Response and Assertion signature to signed.
- Send groups if you want roles. Add a Group Attribute Statement named
groupsand filter it to the groups you want to map. - Copy the Metadata URL from the app's Sign On tab.
- In Avaloi, open Company settings, then Single sign-on, then Enable. Paste the metadata URL, list your email domains, and save.
- Add the DNS TXT record Avaloi shows under Domain proof, choose Verify domain, then choose Test connection.
- Sign in once through Sign in with your company. When that works, turn on Mandatory single sign-on if you want it.
Quick answers
Where do I find the ACS URL? On Company settings, then Single sign-on, under Details for your identity provider. It is made before you connect anything.
Avaloi refused the response.
Check that the assertion is signed, that the email is the NameID or the email attribute, and that the email is on a domain you verified. See the fixes in Single sign-on with SAML.
Members are stuck in a loop. The Owner can always sign in with a password. Turn Mandatory single sign-on off, fix the connection, run Test connection, then turn it on again.
API
GET /v1/companies/me/sso/sp-metadataPUT /v1/companies/me/ssoPOST /v1/companies/me/sso/test
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.