Okta

Configure OIDC for Tines

This guide provides instructions on configuring OpenID Connect (OIDC) Single Sign-On (SSO) for the Tines app integration.

Contents


Supported features

Tines supports the following features:

Before you begin

Configure the app in Okta

  1. In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
  2. Click Browse App Catalog.
  3. Search for and select the Tines app.
  4. Click Add Integration.
  5. Enter your Tenant URL without the trailing slash, for example https://acme.tines.com. To locate your Tenant URL, go to https://login.tines.com, enter your email address, and copy the destination URL that follows the redirect.
  6. Click Next.
  7. On the Sign-On Options tab, select OpenID Connect.
  8. Select the desired user or group assignments, and then click Save.
  9. On the Sign On tab (or Authentication tab in Okta Identity Engine), copy your Client ID, Client secret, and your Okta org domain, for example https://acme.okta.com.

Configure OIDC in Tines

  1. In Tines, go to Settings Center, and under Access & security, click Authentication.
  2. Select OIDC as the SSO option.
  3. Enter the Client ID and Client secret that you copied from Okta.
  4. Go to your Okta org's OpenID configuration endpoint, for example https://acme.okta.com/.well-known/openid-configuration, and copy the following values into the matching fields in Tines:
    • Authorization endpoint URL, for example https://acme.okta.com/oauth2/v1/authorize
    • Token endpoint URL, for example https://acme.okta.com/oauth2/v1/token
    • Issuer, for example https://acme.okta.com
    • JSON Web Key Set (JWKS) URL, for example https://acme.okta.com/oauth2/v1/keys

Configure JIT provisioning

You can optionally enable Just-in-Time (JIT) provisioning by mapping Okta groups to Tines teams and roles. When you enable JIT provisioning, users who sign in for the first time are automatically assigned their mapped team and role, without needing an explicit tenant invitation.

  1. On the app's Sign On tab in Okta, enter groups as the value for Scopes to fetch the groups claim during user sign-in.
  2. Enter groups as the value for SSO-group-based access so that user group information is available to Tines at sign-in.
  3. In Tines, select Just-in-time user provisioning in the User provisioning section.
  4. Configure a group mapping that contains at least one entry for mappings, and optionally tenant_owners_groups and tenant_permission. See Automated user provisioning for details about configuring mappings.

To include a group in the ID token's group claim, the Okta group name must start with Tines (case-sensitive), for example Tines-Admins. Okta excludes any group that doesn't have the Tines prefix from the claim.

Verify SP-initiated SSO

Go to your Tines tenant URL, for example https://acme.tines.com. You're directed to your Okta org for authentication. Enter your Okta credentials. You're directed back to Tines and signed in.

Additional information