Okta

Configure SAML 2.0 for Honeycomb

This guide provides instructions on configuring SAML 2.0 Single Sign-On (SSO) for the Honeycomb app integration.

Contents


Supported features

Honeycomb supports the following features:

Prerequisites

Integrate the app in Okta

Retrieve your unique identifier from Honeycomb

  1. In Honeycomb, go to Account > Team Settings.
  2. Select the Team Details view.
  3. In the Single Sign-On section, if your team is already configured to use another SSO provider, turn it off.
  4. Click Enable SSO.
  5. In the SSO provider configuration modal, select SAML/Okta.
  6. Click Next.
  7. Note the unique identifier Honeycomb generates for your team. It appears in the Service Provider Issuer and Service Provider ACS URL values. For example, if your team name is Crewbacca, Honeycomb generates the identifier crewbacca.
  8. Leave this browser tab open. You need the identifier to configure the app in Okta.

Configure the app in Okta

  1. In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
  2. Click Browse App Catalog.
  3. Search for and select the Honeycomb app.
  4. Click Add Integration.
  5. On the General Settings tab, enter the identifier you noted from Honeycomb in the Unique ID field.
  6. Click Next.
  7. Set the user or group assignments for the app, and then click Save.
  8. On the Authentication tab (or the Sign On tab in Okta Classic Engine), copy the Metadata URL. You need it to complete the configuration in Honeycomb.

Configure SAML in Honeycomb

  1. Switch to the browser tab with your Honeycomb Service Provider settings.
  2. In the Identity Provider Metadata URL field, paste the Metadata URL you copied from Okta.
  3. Optionally, select a Default Role to assign to new users who join your team through SSO. If you don't choose a default role, Honeycomb assigns the Read-Only role.
  4. Click Convert to SAML SSO Team.

Configure JIT provisioning

Just-in-Time (JIT) provisioning applies when someone signs in to a new Honeycomb account for the first time. Honeycomb requires the user to confirm their email address before they can sign in.

  1. Assign the user to the app in the Assignments section in Okta.
  2. Sign in to Honeycomb as that user. Honeycomb prompts you to verify the account, because the email address hasn't been confirmed yet.
  3. Check your inbox for the activation code email from Honeycomb, and note the confirmation code in the message.
  4. Enter the confirmation code on the Honeycomb sign-in page, and then click Submit. You're signed in and directed to your team's dashboard.

Verify SP-initiated SSO

  1. Go to your team's SAML sign-in page. Teams in the US use https://ui.honeycomb.io/login/sso/<team_slug>, and teams in the EU use https://ui.eu1.honeycomb.io/login/sso/<team_slug>. For example, to sign in to a US team with the slug hny, go to https://ui.honeycomb.io/login/sso/hny. You're directed to your team's SAML IdP.
  2. Enter your Okta credentials. You're signed in and directed back to the app.

Supported SAML attributes

Honeycomb supports these SAML attributes:

Attribute Value
email user.email
firstName user.firstName
lastname user.lastName