This article describes the legacy Okta setup. Crelate now recommends SAML single sign-on. To set up SAML, see Set up single sign-on (SSO) with SAML (beta).
Crelate supports Okta in two ways. The legacy Okta provider continues to work for existing setups, and SAML single sign-on is the recommended method for new setups, including new Okta setups.
What do you need to set up Okta single sign-on?
A Crelate Enterprise organization license.
Single sign-on turned on for your organization. If Single Sign-On does not appear under Security in Settings, contact your Success Manager or Support.
An Administrator account in your Crelate Enterprise organization.
An Administrator account in your Okta organization.
The same login email for both Administrator accounts, because Crelate uses it to complete the validation process.
The legacy Okta provider supports the Service Provider (SP)-initiated authentication flow.
How to configure Okta
Log in to Okta with your Administrator account.
Go to Applications.
Select Browse App Catalog.
Search for Crelate and select the app.
Select Add Integration in the upper right.
Check both Do not display application icon to users and Do not display application icon in the Okta Mobile App.
Select Done to add the app.
How to assign users to the app in Okta
After you add the app, assign the users who will log in to Crelate with their Okta credentials.
Open the Crelate app under Applications and go to the Assignments tab.
Select Assign, then choose the type you want to assign: a person or a group.
Search for the person or group and select Assign.
Change the assignment fields if needed. The defaults should work for most organizations. Then select Save and Go Back.
Select Done to close the dialog.
How to collect the Okta details you need for Crelate
You need three values to set up the provider in Crelate.
In the Crelate app in Okta, go to the Sign On tab and note the Client ID and Client secret. You can also find them on the General tab.
Copy your organization’s domain URL from your browser’s address bar, without the “admin” section. For example,
https://your-org-name-admin.okta.com/admin/dashboardbecomeshttps://your-org-name.okta.com.
How to add the legacy Okta provider in Crelate
Log in to Crelate with your Administrator account.
Go to Settings > Security > Single Sign-On.
Select Add, then choose the Okta option.
Complete the form. All fields are required.
Select Save.
How to validate the Okta provider
The provider must be validated before you can assign it to users.
Select the Validate icon on the provider. A dialog opens and walks you through signing in to confirm that the configuration works.
Complete the sign-in. After validation succeeds, the provider is enabled for use.
If validation fails, make sure the provider settings in Crelate match the values of the Crelate app in your Okta organization.
How to assign the Okta provider to users
After the provider is validated, assign it to users as their Login Type.
Go to Settings > Security > Users.
Select a user.
In the Login Type drop-down, select the Okta provider you added and validated. The user’s email address in Crelate must match the email address on their Okta account.
Select Save.
Confirm the Login Type change when Crelate prompts you.
Changing a user’s Login Type to an SSO provider sends that user an invitation email. The user must confirm their email address using the link in the invitation, and then complete the login process to finish enabling their Okta credentials for Crelate.
How do users sign in with Okta?
Go to app.crelate.com.
Enter your email address and select Next.
Complete the login on your provider’s sign-in screen.
After you log in successfully, you go directly into Crelate.
Key takeaway
This article covers the legacy Okta provider, which continues to work for existing setups. For new setups, and for any provider that supports SAML, see Set up single sign-on (SSO) with SAML (beta).
















