> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta configuration guide

> Set up Okta single sign-on to Gumloop from the Okta Integration Network

This guide is for Okta administrators who add the **Gumloop** integration from the Okta Integration Network (OIN) and connect it to their Gumloop organization for OpenID Connect (OIDC) single sign-on.

## Prerequisites

* A Gumloop organization on an Enterprise plan, and the **Admin** [organization role](/core-concepts/organization_user_roles#admin) in it.
* Admin access to your Okta org.
* Each member's Okta email must match their Gumloop email. Gumloop matches accounts by email.

## Supported features

* **SP-initiated SSO.** Members start from the Gumloop sign-in page.
* **Just-In-Time provisioning.** A member with no Gumloop account gets one at their first sign-in, unless SCIM provisioning is on.
* **Cross App Access.** Okta can connect Slack and Asana for your members inside Gumloop. See [Cross App Access with Okta](/enterprise-features/idp-guides/cross-app-access-with-okta).

IdP-initiated SSO and Single Logout are not supported. Point Okta dashboard tiles at your Gumloop login page instead.

For more information on the listed features, visit the [Okta Glossary](https://help.okta.com/okta_help.htm?type=oie\&id=ext_glossary).

## Configuration steps

### In Okta

1. In the Okta Admin Console, select *Applications and Resources* > *Applications* and press *Browse App Catalog*.
2. Search for **Gumloop** and press *Add Integration*. Keep the default label and press *Done*.
3. Open the *Assignments* tab and assign the people or groups who should sign in to Gumloop.
4. Open the *Sign On* tab and copy the **Client ID** and the **Client secret**. Note your **Okta domain** as well, the hostname of your Okta org, such as `acme.okta.com`.

### In Gumloop

1. Go to [gumloop.com/settings/organization/sso](https://www.gumloop.com/settings/organization/sso) and press **Set up OpenID Connect**.
2. Press **Continue** through the two steps that describe creating an app in Okta. The catalog integration already covers them.
3. Under **App credentials**, enter the **Okta domain**, **Client ID**, and **Client Secret** from Okta, then press **Save app**. Gumloop verifies them with Okta before saving.
4. Under **Choose SSO domains**, turn on each email domain that should sign in through Okta.
5. Under **Test sign-in**, press **Run test** and sign in to Okta as yourself. The test must pass before you can continue.
6. Review the **Pre-flight checks**, then press **Activate Okta OIDC sign-in**.

Members on the SSO domains sign in through Okta from their next full sign-in. The change can take up to five minutes to take effect. For the full reference, see [Setting up OIDC](/enterprise-features/sso_saml_oidc_scim#setting-up-oidc).

## SP-initiated SSO

1. Go to your organization's Gumloop login page, `gumloop.com/signin/{your-slug}`, or to [gumloop.com/signin](https://www.gumloop.com/signin).
2. Enter your work email and press **Sign in with SSO**.
3. Sign in to Okta if asked.

You land on your Gumloop home page.

## Troubleshoot

| Message | What to do |
| - | - |
| "You need access to Gumloop in Okta" | The user is not assigned to the Gumloop app. Add them, or their group, on the app's *Assignments* tab. |
| "Okta signed in a different account" | The user signed in to Okta with an email that does not match their Gumloop email. Sign in to Okta as the matching account. |
| Okta rejected the client ID and secret | Copy both again from the app's *Sign On* tab in Okta. |
| Domain does not answer as an Okta org authorization server | Enter the bare hostname, such as `acme.okta.com`, without `https://` or any path. |

For anything else, contact [support@gumloop.com](mailto:support@gumloop.com).
