Use one set of credentials to conveniently access Startly via your Okta instance. Startly utilizes OpenID Connect (OIDC) for the Okta integration for SSO.
Set-Up Instructions
In Okta Admin console
- Open the Okta Admin Console
- Select Applications from the left nav menu
- Select Applications from the sub menu of Applications in the left nav menu
- Click the Create App Integration button
data:image/s3,"s3://crabby-images/861bf/861bf10b5239ba432a6dc9edb3e0e0484bf4c9af" alt="Okta Admin Console - Applications"
- Create a new app integration by:
- Under Sign-in method, select OIDC – OpenID Connect
- Under Application type, select Web Application
- Click on the Next button
data:image/s3,"s3://crabby-images/f8f04/f8f048949437d759432739fc624d8aa308cc178f" alt="Create a New App Integration Settings"
- New Web App Integration Form:
- Under General Settings, enter a name for your App integration (e.g. Startly)
- Under Grant type, select Authorization Code
- Nothing is needed at this point for the Sign-In or the Sign-Out URIs, we will come back for these later in the process.
- Under the Assignments section, select Allow everyone in your organization to access
- Make sure Enable immediate access with Federation Broker Mode is selected.
- Click on the Save button
data:image/s3,"s3://crabby-images/cd61f/cd61f3ff7998a39202d5d74476050b06dd115640" alt=""
- From the Integration Page:
- Copy the Client ID and paste it to Notepad to enter later into Startly.
- Copy the Client Secret and paste it to Notepad to enter later into Startly.
data:image/s3,"s3://crabby-images/5a5c6/5a5c670ca8926020cc4d8513fb735ae5d2407cd9" alt="Copy Client ID and Client Secret"
In Startly
data:image/s3,"s3://crabby-images/7a592/7a592bd6ff7213275fc65c00bc0cbef198b31661" alt=""
- Click on the Settings menu from the left nav.
- Select the Integrations category.
- Select the Authentication setting.
- Click the + Icon to add a new authentication
- Enter the SSO Description (e.g. Okta)
- Select the Provider – OIDC
- Confirm that the Use Discovery feature is turned on.
- Enter the following in the Discovery endpoint url: https://organization_subdomain.okta.com/.well-known/openid-configuration. Make sure to replace the organization subdomain in the url with your Okta instance subdomain.
- Confirm the URL was verified. A green checkmark should appear when verified.
- From Notepad, copy the Client ID into the Client ID field in Startly.
- From Notepad, copy the Client Secret into the Client Secret field in Startly.
- Click Save
data:image/s3,"s3://crabby-images/dfc96/dfc96bfe537284baee8e9c9c7730ac6c61b72114" alt=""
From Startly to Okta
- In Startly:
- Open the Authentication Configuration you just created.
- Copy the read only Redirect URL field to Notepad to enter into Okta.
data:image/s3,"s3://crabby-images/b7396/b7396489bee931d4207a97b178980e355bd5a9d1" alt=""
- In the Okta Admin Console
- From the App Integration page, click Edit in the upper right of the General Settings section.
- In the Sign-in redirect URIs field, paste the Redirect URL copied from Startly.
- In the Sign-out redirect URIs field, paste the Redirect URL copied from Startly and add /logout_response to the end of the Redirect.
- Click Save.
data:image/s3,"s3://crabby-images/953ce/953ce61680a5e56d968861bb5e0db56acdc1cb69" alt="Select Edit"
data:image/s3,"s3://crabby-images/b3db9/b3db99f4fe5cf4a2990877bab13bb83cf13e0346" alt="Update Sign-In and Sign-out Credentials"