Okta SAML SSO setup
Use this page when your IT team is creating an Okta SAML 2.0 app integration for Artifactive. Your Artifactive dashboard shows the setup values for your tenant, and we can help if your team wants an assisted setup.
How setup works
- Artifactive provides service-provider values in the dashboard.
- Your Okta admin creates a SAML 2.0 app integration.
- Your Okta admin enters the Artifactive ACS URL as the Single sign-on URL.
- Your Okta admin enters the Artifactive Entity ID as the Audience URI.
- Your Okta admin assigns the users or groups that should have access.
- Artifactive records the Okta identity-provider metadata.
- An Owner runs Test SSO in Artifactive before enabling SSO-only access.
Values from Artifactive
| Value | How it is used |
|---|---|
| Single sign-on URL | Paste the Artifactive ACS URL into Okta as the Single sign-on URL. |
| Audience URI (SP Entity ID) | Paste the Artifactive Entity ID into Okta as the Audience URI. |
| Name ID format | Use email address if Okta asks. |
| Default RelayState | Leave blank unless Artifactive provides one. |
Values from your identity provider
- Okta Identity Provider metadata URL or metadata XML, preferred.
- Okta Identity Provider Issuer.
- Okta SSO URL.
- Okta x.509 signing certificate.
- Assigned users or groups.
Okta notes
- Create a SAML 2.0 app integration.
- Use the Artifactive ACS URL for Single sign-on URL.
- Use the Artifactive Entity ID for Audience URI.
- Leave Default RelayState blank unless Artifactive provides one.
- Assign the users or groups that should open Artifactive dashboards.
Testing before enforcement
- Run Test SSO from Artifactive.
- Test with an assigned user on an approved company email domain.
- Do not switch to SSO-only until the test passes.
- For team SSO-only, confirm Owner access and recovery before enforcing it.
Common setup issues
- User is not assigned to the SAML app.
- ACS URL or Entity ID does not exactly match.
- NameID/email is missing or not the user's work email.
- Metadata or signing certificate changed after setup.