Okta is a first-class enterprise connection over SAML 2.0. Users whose email domain matches the connection sign in through their Okta org. MFA, session length, and lifecycle stay on the customer's IdP.
Open the connection
In the Authdog console:
- Select the project and environment.
- Open Authentication > Providers. The Enterprise filter is pre-selected by that link.
- Choose Okta.
- Copy the service-provider values Authdog displays: SP-initiated sign-in URL, ACS / Reply URL, SP Entity ID, and the downloadable SP metadata XML.
- Follow the Okta setup guide linked from the connection form for the IdP-side app. Paste Authdog's values into Okta exactly.
Send Okta's values back
Provide Authdog with:
- IdP SSO URL
- IdP X.509 signing certificate
- Connection name
You can import IdP metadata from a URL or paste metadata XML. Import fills the SSO URL, certificate, entity ID, and logout URL when you select Fetch or Parse & autofill. It does not refresh itself later. Re-import when Okta rotates the certificate.
Prefer RSA-SHA256 and SHA-256 if you turn on request signing.
Route by email domain
In Email domains (for SSO discovery), enter one or more domains separated by commas:
acme.com, eu.acme.comAn entry matches that domain and its subdomains. Only active enterprise connections participate. Do not overlap domains across connections. Resolution uses the first active match.
Test it
- Use the connection's Test action.
- Complete an SP-initiated sign-in.
- Confirm Okta sends a stable subject and an email claim.
- Exercise the customer's MFA and sign-out if you enabled logout.
- Repeat in production with production URLs. A custom domain change can change the callback. Update Okta with the URL currently shown in the form.
Related
| Read | To learn how to |
|---|---|
| Enterprise SSO | SAML fields, domain routing, and certificate rotation |
| Marketplace | The listing for this integration |
| Provisioning | SCIM from the same Okta org |