> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML with Okta

> Configure SAML single sign-on to Gumloop with Okta

This guide walks an Okta administrator through connecting Okta to Gumloop for SAML single sign-on: you create an *Application* in Okta, then swap details between your Gumloop SSO setup page and Okta.

## Before you start: get your SP details from Gumloop

A Gumloop organization admin generates an SSO setup link at [gumloop.com/settings/organization/sso](https://www.gumloop.com/settings/organization/sso) (see [SSO, SAML & SCIM](/enterprise-features/sso_saml_scim)). The setup page shows the two Service Provider values you'll copy into Okta:

* **Assertion Consumer Service (ACS) URL** — ends in `/acs`
* **SP Entity ID** — the same URL without the `/acs` suffix

The same page has the fields for the values Okta produces: **Redirect URL**, **IDP Entity ID**, and the **Certificate** upload.

<Steps>
  ### Create an application in Okta

  To create an *Application* in Okta, select *Applications* > *Applications* in the left nav panel.

  <Frame caption="Selecting Applications > Applications from the left navigation panel">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta0.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=e24352abc2c57f5d4642da4a041d3f3f" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta0.png" />
  </Frame>

  You'll land on a page with a bold **Applications** header. Right under the header, select the dark blue button that reads *Create App Integration*.

  <Frame caption="Instructing Okta to create an app integration">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta1.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=be911c76231d76fff96270eac4ceb037" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta1.png" />
  </Frame>

  Okta will flash a modal offering you several radio button choices. Of these, select *SAML 2.0* and then press *Next* in the lower right corner.

  <Frame caption="Telling Okta to use SAML 2.0">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta2.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=6c0f5b96f6811016c75c4340b008b1e8" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta2.png" />
  </Frame>

  Once you've selected *SAML 2.0*, Okta will change the header to read *Create SAML Integration* as below. Okta requires a display name. Write "Gumloop".

  <Frame caption="Assigning the application a display name in Okta">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta3.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=a783b08851af0fac2656714e6ea0c79a" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta3.png" />
  </Frame>

  The remaining options on this page aren't especially important; select *Next* here, which finalizes creation of an Okta *Application*.

  <Frame caption="Selecting Next to move on and adjust the SAML settings">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta4.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=76b089fe32fb76b74b2aad4d86edd72b" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta4.png" />
  </Frame>

  ### Enter Gumloop details in Okta

  Hitting *Next* on the prior page will have nudged you into a new tab, marked *Configure SAML*. Here, you'll copy two pieces of data from your Gumloop SSO setup page into Okta.

  At the top of the page, Okta asks for a *Single sign-on URL*. This is what Gumloop calls the *Assertion Consumer Service (ACS) URL*. It ends in `/acs`. Copy it from your Gumloop SSO setup page and paste it where Okta has written *Single sign-on URL*.

  <Frame caption="Pasting the ACS URL into Okta's Single sign-on URL field">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta5.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=4d3ead3eb269507d24d2962f0f714819" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta5.png" />
  </Frame>

  From here, proceed to the next field on the same page. It reads *Audience URI (SP Entity ID)*. Gumloop calls this the *SP Entity ID*. You'll find it directly under the *Assertion Consumer Service (ACS) URL* on the setup page. It usually looks just like the ACS URL, except it does not end in `/acs`.

  Paste the *SP Entity ID* URL into Okta's *Audience URI (SP Entity ID)* field.

  <Frame caption="Pasting the SP Entity ID into Okta's Audience URI (SP Entity ID) field">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta6.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=6dd1cf6151369970bb4e4b8a32744695" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta6.png" />
  </Frame>

  Once you've filled the *Audience URI (SP Entity ID)* field (and scrolled down to hit *Next* in the lower right corner), you've completed all the necessary data entry from Gumloop into Okta.

  ### Enter Okta details in Gumloop

  Okta requires one brief detour wherein you supply feedback to their team.

  Select *I'm an Okta customer adding an internal app*, skip the remaining questions, scroll down, and press *Finish* in the lower right corner.

  <Frame caption="Selecting 'I'm an Okta customer adding an internal app'">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta8.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=d32556608db61a0c377b359994262f39" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta8.png" />
  </Frame>

  Now you can enter Okta data into Gumloop. The previous step will have routed you to a page with the application's name at the top.

  From here, scroll down a bit and hit *More details*. It's not always easy to see.

  <Frame caption="Scrolling down to find the 'More details' option for the SAML application">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta9b.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=bb995a9f1d7f6571fe870e53afec49ad" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta9b.png" />
  </Frame>

  Once you've expanded the details for the SAML application, you'll see a bunch of data.

  Directly under the *More details* button, there's a URL marked *Sign on URL* with a light purple *Copy* button. Gumloop calls this the *Redirect URL*. Copy this URL and paste it into your Gumloop SSO setup page as the *Redirect URL*.

  <Frame caption="Copying Okta's 'Sign on URL'; this will be the Redirect URL in Gumloop">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta10.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=8f680534150b1be0be6fad68ed6e07e9" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta10.png" />
  </Frame>

  Scrolling further down, you'll see a similar line for a URL that Okta labels *Issuer*. Gumloop calls this the *IDP Entity ID*. Copy this *Issuer* URL and paste it into your Gumloop SSO setup page as the *IDP Entity ID*.

  <Frame caption="Copying Okta's 'Issuer' URL; this will be the IDP Entity ID in Gumloop">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta11.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=2f9484500ba6545b47a8c5443755c66a" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta11.png" />
  </Frame>

  Finally, Gumloop requires a Certificate. You'll find this further down on the same page in Okta. Okta labels it the *Signing Certificate.* (Please be aware that Okta has several related buttons that will not give you what you need.) Press the rectangular *Download* button, which will download an `okta.cert` file.

  Upload `okta.cert` to your Gumloop SSO setup page as the Certificate for this SAML Connection.

  <Frame caption="Downloading okta.cert from Okta's SAML configuration page">
    <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-assets/okta/okta12.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=a325f9294ea3b46587a2b1e5c5b4899c" width="1920" height="1080" data-path="images/idp-guides/idp-assets/okta/okta12.png" />
  </Frame>

  Once you've uploaded the Certificate, you've finished the SAML configuration. Remember that an Okta administrator still has to assign users to the application before they can sign in.
</Steps>
