How to Set Up Single Sign-on with Okta

Okta provides secure identity management and single sign-on for web and mobile applications. With the Oktopost Okta app, you can easily set up single sign-on with Okta serving as your Identity Provider.

Prerequisites

To set up the integration you need to have admin access to both Oktopost and Okta.

Supported Features

The Oktopost Okta app currently supports the following features: 

  • Service Provider (SP) initiated SSO
  • Identity Provider (Idp) initiated SSO

For more information on the listed features, visit the Okta Glossary.

Configuration steps

  1. Log into your Oktopost account as an administrator.
  2. Go to Settings > Security > Single Sign-on.
  3. Select Yes from the Enable Single Sign-on drop-down menu.
  4. Enter the following information from the Sign On application tab of the Okta Admin Dashboard:
    1. SAML endpoint
    2. Issuer URL
    3. X-509 Certificate, saved as okta.cert
  5. Do not check Require SSO until you have tested SAML successfully.
  6. Make sure to save your changes. 

European Customers

If you log into Oktopost through eu-app.oktopost.com or eu-board.oktopost.com then you will need to create a custom Okta app in order to log via SSO. 

Creating a custom Okta app

  1. Create a new app integration  with sign in method: SAML 2.0 and a custom name (maybe: Oktopost SSO)
  2. In the Configure SAML section, use the following details:
    1. Single sign-on URL: https://eu-app.oktopost.com/auth/acs  
    2. Audience URI (SP Entity ID): urn:oktopost:sp
    3. Default Relay State: 1 (or 2 if setting up SSO for the board

Notes

SP-initiated SSO

To log into Oktopost via SSO, navigate to https://app.oktopost.com/auth/login-sso and enter your SSO email before clicking Sign in. 

Advocacy Board

If you want to set the Okta app to log in to https://board.oktopost.com, in Okta, set the Default Relay State to 2. Without this field set, it will log in to https://app.oktopost.com by default.

Was this article helpful?
0 out of 0 found this helpful