๐๏ธOkta Integration
This article describes the process of integrating Arnica with Okta SSO
Okta integration instructions
By integrating Arnica with Okta single sign on (SSO) you can ensure that all users authenticating with Arnica are doing so through your organizations-managed Okta provisioning and de-provisioning. The setup of the integration requires taking steps on Arnica and Okta. Below are the details.
Get organization identified in Arnica
Sign into Arnica https://app.arnica.io/ and click on your avatar.
Select Edit Account
Copy the Organization ID (we will call it
YOUR_ARNICA_ORGANIZATION_ID
in the next steps in this guide).
Add app integration in Okta
The following steps must be completed by an Okta administrator:
Go to the following URL: https://{YOUR_OKTA_ADMIN_DOMAIN}.okta.com/admin/apps/active. For example: https://company-admin.okta.com/admin/apps/active. This page will result in a 404 error if you do not have permissions.
Click on Create App Integration button.
In the dialog that opens, select SAML 2.0
In General Settings, set the following:
App name: Arnica App logo: you can download the logo from here and upload it to Okta
In Configure SAML -> A: SAML Settings
In General
A. Single sign-on URL: enter
https://arnica-prod.us.auth0.com/login/callback?connection={YOUR_ARNICA_ORGANIZATION_ID}
B. Audience URI (SP Entity ID): enter
urn:auth0:arnica-prod:{YOUR_ARNICA_ORGANIZATION_ID}
C. Leave the other fields with their default value.In โAttribute Statements (optional)โ: add the following mappings (These statements are case sensitive)
A. email -> user.email
B. given_name -> user.firstName
C. family_name -> user.lastName
D. email_verified -> true E. groups -> user.groups
Click Next (Though the section title says โOptionalโ this step is required for Arnica integration)
In Feedback
A. Are you a customer or partner? Mark โI'm an Okta customer adding an internal appโ
B. Leave other fields empty and click Finish
Under Sign On -> Settings -> Sign on methods -> SAML 2.0, click on More details
1. Copy the Sign on URL
2. Download the Signing Certificate
Send the following to support@arnica.io the following information.
Subject: SSO Onboarding Request
Email domain: the domain for which you would like to setup SSO, e.g., yourcompany.com
Arnica Organization ID: your arnica organization ID obtained earlier.
Sign on URL: the Sign on URL from the step above.
Attach the Signing Certificate from the step above.
Leave a contact phone number and available times for Arnicaโs customer success to help with the onboarding process.
We are typically fast at responding to these requests, but please allow up to 1-2 business days to get confirmation.
Last updated