> For the complete documentation index, see [llms.txt](https://docs.birdie.so/birdie-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.birdie.so/birdie-docs/security/saml-sso/setup-sso-with-okta.md).

# Setup SSO with Okta

Follow these steps in your Okta account:<br>

1. Create a new App Integration in Okta and choose the SAML2 option\
   \
   ![](https://3843507234-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FECPgvsGwy5oMz4WIZw3a%2Fuploads%2FoB8E8DrrVNSIsyhYpYHM%2FScreenshot%202024-11-18%20at%2011.14.33.png?alt=media\&token=249e0fec-6081-4829-8630-b9f824d2025d)<br>
2. Give it a name, and when asked for `Single sign-on URL` paste Birdie's Service Provider ACS, when asked for the`Audience URI (SP Entity ID)` paste Birdie's Service Provider EntityID, as illustrated in the following screenshot. Let everything else as-is with Okta defaults… \
   \
   ![](https://3843507234-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FECPgvsGwy5oMz4WIZw3a%2Fuploads%2FjDNdREBMQZPJ6e3xYmRU%2FScreenshot%202024-11-18%20at%2011.17.54.png?alt=media\&token=07a21a59-bc5c-4dda-bb41-d56a9bae0d21)<br>
3. Now your app is created on Okta side, go back Enable SAML2 into your Birdie settings, that will open a form where you must enter a few informations: at first you can label this connection as you wish, call it "Okta" for example, and add your domain name (separated with commas if you get some). \
   \
   You will then need to fill-in 3 fields in Birdie with infos coming from your Okta app: \
   1\. the field <mark style="background-color:yellow;">Entity ID</mark> (called *"Issuer"* in Okta) \
   2\. the field <mark style="background-color:yellow;">Single SignOn URL</mark> (called *"Sign on URL"* in Okta)\
   3\. the field <mark style="background-color:yellow;">X.509 certificate</mark>: to do this, download your Okta Signin Certificate (do not click on Copy, but download the file), open this file in a text editor, and copy the whole text content of your certificate into Birdie's X.509 certificate field. \
   Once you get those 3 informations in Birdie, click the Enable SAML button. \
   \
   ![](https://3843507234-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FECPgvsGwy5oMz4WIZw3a%2Fuploads%2Fwjw9H3SeSteBddqad27X%2FScreenshot%202025-08-20%20at%2004.40.31.png?alt=media\&token=3f005e4c-644d-405e-9c1f-20082d1e5e9e)<br>
4. If there was no error, you should be able to connect to Birdie with your SSO.
