Okta SSO
Create an Okta SAML or OIDC app, give it the Avaloi ACS and start URLs, and paste the issuer into Avaloi.
Create an Okta app, then paste its issuer or metadata URL into Avaloi. Only the Owner can save the connection.
Connect Okta
- Create an app in Okta. Use a SAML 2.0 app or an OIDC web app. Assign it to the groups who should reach Avaloi.
- Add the Avaloi URLs. For SAML, set the Assertion Consumer Service to
https://api.avaloi.com/auth/saml/{company}/acsand the start URL tohttps://api.avaloi.com/auth/saml/{company}/start. Replace{company}with your company slug. - Map email as the NameID. Avaloi matches users on verified email.
- Copy the metadata. For SAML, copy the metadata URL. For OIDC, copy the issuer (your Okta org URL).
- Save in Avaloi. Open Company settings, then SSO. Choose SAML or OIDC, paste the issuer or metadata URL, add your email domains, and save.
- Test, then enforce. Sign out and sign in through Okta. When that works, turn on Enforce SSO.
Quick answers
Where do I find my company slug?
It is the slug field in the response to GET /v1/companies/me.
The login loops back to Okta. Turn Enforce SSO off. Check the ACS, the issuer, and that assertions are signed with the email as NameID. Test again, then enforce. See SSO.
SAML or OIDC? Either works. Pick the one your Okta admin already manages.
API
GET /v1/companies/me/ssoPUT /v1/companies/me/sso
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.