Okta is a first-class enterprise connection over SAML 2.0. Users whose email domain matches the connection sign in through their Okta org. MFA, session length, and lifecycle stay on the customer's IdP.

## Open the connection

In the [Authdog console](https://console.authdog.com/dashboard/authentication?tab=providers&category=enterprise):

1. Select the project and environment.
2. Open **Authentication > Providers**. The Enterprise filter is pre-selected by that link.
3. Choose **Okta**.
4. Copy the service-provider values Authdog displays: SP-initiated sign-in URL, ACS / Reply URL, SP Entity ID, and the downloadable SP metadata XML.
5. Follow the Okta setup guide linked from the connection form for the IdP-side app. Paste Authdog's values into Okta exactly.

## Send Okta's values back

Provide Authdog with:

- IdP SSO URL
- IdP X.509 signing certificate
- Connection name

You can import IdP metadata from a URL or paste metadata XML. Import fills the SSO URL, certificate, entity ID, and logout URL when you select **Fetch** or **Parse & autofill**. It does not refresh itself later. Re-import when Okta rotates the certificate.

Prefer RSA-SHA256 and SHA-256 if you turn on request signing.

## Route by email domain

In **Email domains (for SSO discovery)**, enter one or more domains separated by commas:

```text
acme.com, eu.acme.com
```

An entry matches that domain and its subdomains. Only active enterprise connections participate. Do not overlap domains across connections. Resolution uses the first active match.

## Test it

1. Use the connection's **Test** action.
2. Complete an SP-initiated sign-in.
3. Confirm Okta sends a stable subject and an email claim.
4. Exercise the customer's MFA and sign-out if you enabled logout.
5. Repeat in production with production URLs. A [custom domain](/docs/custom-domains) change can change the callback. Update Okta with the URL currently shown in the form.

## Related

| Read | To learn how to |
| --- | --- |
| [Enterprise SSO](/docs/sso) | SAML fields, domain routing, and certificate rotation |
| [Marketplace](/marketplace/okta) | The listing for this integration |
| [Provisioning](/docs/concepts/provisioning) | SCIM from the same Okta org |
