Configure Okta as SAML Identity Provider

Before you start

You can configure Okta as a SAML identity provider (IdP) in Auth0 by configuring a SAML Enterprise connection.

Configure Okta SAML app integration

You can create a SAML app integration in the Okta Developer Console.

Create app integration

  1. Log in to the Okta Developer Console.

  2. Go to Create App Integration and choose SAML 2.0 from the options.

  3. Configure the following settings:

    Setting Description Example
    Single Sign-On URL Auth0 tenant login callback URL. https://{yourAuth0Domain}/login/callback?connection={yourAuth0ConnectionName}
    Audience URI (SP Entity ID) Auth0 connection audience value. urn:auth0:{yourAuth0TenantName}:{yourAuth0ConnectionName}

  4. Select Next, and then select Finish to complete the Okta app integration configuration.

Record SSO URL and download certificate

The login flow is now directed to the Sign On page for the newly-created app.

  1. Select View SAML Setup Instructions.

  2. Record the Identity Provider Single Sign-On URL.

  3. Download the X.509 Certificate in PEM or CER format.

  4. Navigate to Assignments, and then assign a user to the Okta application.

Configure SAML connection in Auth0

You can create a SAML Enterprise connection in the Auth0 Dashboard.

  1. Log in to the Auth0 Dashboard.

  2. Go to Authentication > Enterprise.

  3. Select Create (+ button) next to SAML.

  4. Configure the following settings:

    Setting Description Example
    Connection name Auth0 connection name. myoktaconnection
    Sign In URL Okta URL where user login requests are sent.

    This is the Identity Provider Single Sign-On URL value you recorded previously.
    https://my_okta_tenant_name.okta.com/app/ my_okta_tenant_namemy_okta_saml_app_integration_name/ dakflkbzevu5i5zBi939/sso/saml
    X509 Signing Certificate Okta tenant public key signing certificate.

    Upload the X509 Certificate you downloaded previously.
    myOktaTenantSigningCertificate.pem

  5. Select Create.

Enable SAML Enterprise connection in Auth0

You can enable your SAML Enterprise connection in the Auth0 Dashboard.

Enable SAML Enterprise connection when using Organizations

If you’re using Organizations:

  1. Log in to the Auth0 Dashboard.

  2. Go to Organizations, and select your Organization.

  3. Switch to the Connections view.

  4. Select Enable Connections.

  5. Select the SAML connection you created previously, and then select Enable Connection.

Enable SAML Enterprise connection when not using Organizations

If you’re not using Organizations:

  1. Log in to the Auth0 Dashboard.

  2. Go to Authentication > Enterprise > SAML, and select the SAML connection you created previously.

  3. Switch to the Applications view, and enable the connection for your chosen application(s).

Test connection

You can test your connection in the Auth0 Dashboard.

  1. Log in to the Auth0 Dashboard.

  2. Go to Authentication > Enterprise > SAML.

  3. Locate your connection in the list.

  4. Select More Actions (... button), and then select Try.

    • If your connection is configured correctly, you'll see the It works! screen.

    • If not, you’ll see an error message with details about what went wrong.