Skip to main content

Add Okta as a Single Sign-On Provider (legacy)

Set up the legacy Okta single sign-on provider in Crelate. Requires the Enterprise plan with SSO turned on. For new setups, use SAML.

L
Written by Lauren Hickey-Jednat

This article describes the legacy Okta setup. Crelate now recommends SAML single sign-on. To set up SAML, see Set up single sign-on (SSO) with SAML (beta).

Crelate supports Okta in two ways. The legacy Okta provider continues to work for existing setups, and SAML single sign-on is the recommended method for new setups, including new Okta setups.

What do you need to set up Okta single sign-on?

  • A Crelate Enterprise organization license.

  • Single sign-on turned on for your organization. If Single Sign-On does not appear under Security in Settings, contact your Success Manager or Support.

  • An Administrator account in your Crelate Enterprise organization.

  • An Administrator account in your Okta organization.

  • The same login email for both Administrator accounts, because Crelate uses it to complete the validation process.

The legacy Okta provider supports the Service Provider (SP)-initiated authentication flow.


How to configure Okta

  1. Log in to Okta with your Administrator account.

  2. Go to Applications.

  3. Select Browse App Catalog.

  4. Search for Crelate and select the app.

  5. Select Add Integration in the upper right.

  6. Check both Do not display application icon to users and Do not display application icon in the Okta Mobile App.

  7. Select Done to add the app.


How to assign users to the app in Okta

After you add the app, assign the users who will log in to Crelate with their Okta credentials.

  1. Open the Crelate app under Applications and go to the Assignments tab.

  2. Select Assign, then choose the type you want to assign: a person or a group.

  3. Search for the person or group and select Assign.

  4. Change the assignment fields if needed. The defaults should work for most organizations. Then select Save and Go Back.

  5. Select Done to close the dialog.


How to collect the Okta details you need for Crelate

You need three values to set up the provider in Crelate.

  1. In the Crelate app in Okta, go to the Sign On tab and note the Client ID and Client secret. You can also find them on the General tab.

  2. Copy your organization’s domain URL from your browser’s address bar, without the “admin” section. For example, https://your-org-name-admin.okta.com/admin/dashboard becomes https://your-org-name.okta.com.


How to add the legacy Okta provider in Crelate

  1. Log in to Crelate with your Administrator account.

  2. Go to Settings > Security > Single Sign-On.

  3. Select Add, then choose the Okta option.

  4. Complete the form. All fields are required.

    • Display Name: Enter any name that helps you identify the provider. This name appears when you assign the provider to users.

    • Domain: Enter the full domain URL, including the “https” portion.

    • Client ID and Client Secret: Enter the values from Okta.

  5. Select Save.


How to validate the Okta provider

The provider must be validated before you can assign it to users.

  1. Select the Validate icon on the provider. A dialog opens and walks you through signing in to confirm that the configuration works.

  2. Complete the sign-in. After validation succeeds, the provider is enabled for use.

If validation fails, make sure the provider settings in Crelate match the values of the Crelate app in your Okta organization.


How to assign the Okta provider to users

After the provider is validated, assign it to users as their Login Type.

  1. Go to Settings > Security > Users.

  2. Select a user.

  3. In the Login Type drop-down, select the Okta provider you added and validated. The user’s email address in Crelate must match the email address on their Okta account.

  4. Select Save.

  5. Confirm the Login Type change when Crelate prompts you.

Changing a user’s Login Type to an SSO provider sends that user an invitation email. The user must confirm their email address using the link in the invitation, and then complete the login process to finish enabling their Okta credentials for Crelate.


How do users sign in with Okta?

  1. Enter your email address and select Next.

  2. Complete the login on your provider’s sign-in screen.

After you log in successfully, you go directly into Crelate.


Key takeaway

This article covers the legacy Okta provider, which continues to work for existing setups. For new setups, and for any provider that supports SAML, see Set up single sign-on (SSO) with SAML (beta).


What's Next?

Did this answer your question?