Configure OIDC for Domo
This guide provides instructions on configuring OpenID Connect (OIDC) Single Sign-On (SSO) for the Domo app integration.
Contents
Supported features
Domo supports the following features:
- SP-initiated SSO
- Just-In-Time (JIT) provisioning
Prerequisites
- You have an Okta admin role with permission to manage apps.
- You have the Admin system role in Domo, or a custom role with the Manage All Company Settings grant.
- You know your Domo subdomain. For example, if your Domo URL is
https://xyz.domo.com, your subdomain is xyz.
Integrate the app in Okta
- In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
- Click Browse App Catalog.
- Search for and select the Domo app.
- Click Add Integration.
- On the General Settings page, complete the following:
- Application label: Optionally, enter a name to identify this integration.
- Subdomain: Enter your Domo subdomain. For example, enter
xyz if your Domo URL is https://xyz.domo.com.
- Click Next.
- On the Sign-On Options page, select OpenID Connect.
- Set the user or group assignments for the app, and then click Save.
- Open the Sign On tab (or the Authentication tab in Okta Identity Engine) for the app and copy the following values. You need them to complete the configuration in Domo:
- Client ID
- Client secret
- Your Okta org domain, for example
https://xyz.okta.com
Configure OIDC in Domo
- Sign in to Domo.
- Go to Admin > Authentication > Single Sign-On (SSO).
- On the Configuration tab, find the OIDC item and click Configure.
- If you've already configured OIDC, click the vertical ellipsis and select Edit.
- Select Well-Known Config.
- In the Well-known config URL field, enter your Okta well-known configuration endpoint:
<your-okta-org-domain>/.well-known/openid-configuration, where <your-okta-org-domain> includes https://. For example, https://xyz.okta.com/.well-known/openid-configuration.
- In the Client ID field, paste the Client ID you copied from Okta.
- In the Client Secret field, paste the Client secret you copied from Okta.
- Click Save, and then click Save and enable OIDC.
Verify SP-initiated SSO
Go to https://<your-subdomain>.domo.com and click Sign-On. You're directed to your Okta org automatically. Enter the credentials of a user who's assigned to the Domo app in Okta, and then click Sign in. You're automatically signed in to Domo and you're directed back to the app.
See Domo SSO.