Users whose email domain matches the connection sign in through their Okta org. MFA, session length, and lifecycle stay on the customer's IdP.
Open the connection
In the Authdog console:
- Select the project and environment.
- Open Authentication > Providers. The Enterprise filter is pre-selected by that link.
- Choose Okta.
- Copy the service-provider values Authdog displays: SP-initiated sign-in URL, ACS / Reply URL, SP Entity ID, and the downloadable SP metadata XML.
- Follow the Okta setup guide linked from the connection form for the IdP-side app. Paste Authdog's values into Okta exactly.
Send Okta's values back
Provide Authdog with:
- IdP SSO URL
- IdP X.509 signing certificate
- Connection name
You can import IdP metadata from a URL or paste metadata XML. Import fills the SSO URL, certificate, entity ID, and logout URL when you select Fetch or Parse & autofill. It does not refresh itself later. Re-import when Okta rotates the certificate.
Prefer RSA-SHA256 and SHA-256 if you turn on request signing.
Route by email domain
In Email domains (for SSO discovery), enter one or more domains separated by commas:
acme.com, eu.acme.comAn entry matches that domain and its subdomains. Only active enterprise connections participate. Do not overlap domains across connections. Resolution uses the first active match.
Test it
- Use the connection's Test action.
- Complete an SP-initiated sign-in.
- Confirm Okta sends a stable subject and an email claim.
- Exercise the customer's MFA and sign-out if you enabled logout.
- Repeat in production with production URLs. A custom domain change can change the callback. Update Okta with the URL currently shown in the form.
Related
| Read | To learn how to |
|---|---|
| Enterprise SSO | SAML fields, domain routing, and certificate rotation |
| Marketplace | The listing for this integration |
| Provisioning | SCIM from the same Okta org |