Configure SAML 2.0 for dbt Cloud
This guide provides instructions on configuring SAML 2.0 Single Sign-On (SSO) for the dbt Cloud app integration.
Contents
Supported features
dbt Cloud supports the following features:
- SP-initiated SSO
- IdP-initiated SSO
- Just-in-Time (JIT) provisioning
Prerequisites
- You have an Okta admin role with permission to manage apps.
- You have admin access to your dbt Cloud account.
Integrate the app in Okta
Retrieve your account-specific values from dbt Cloud
- Sign in to dbt Cloud.
- Go to Account Settings > SSO & SCIM, select Edit, and then select Okta as your IdP.
- In Identity provider values, note the Auth0 URI, Auth0 EntityID, and Login Slug values. You need them to complete the configuration in Okta.
Save the sign-in URL that's displayed on this page. You need it later to verify SSO.
dbt Cloud displays your Single sign-on URL and Audience URI (SP Entity ID) on this screen, based on those values:
- Single sign-on URL:
https://<auth0_uri>/login/callback?connection=<login_slug>, for example https://auth.test.com/login/callback?connection=okta-test-new
- Audience URI (SP Entity ID):
urn:auth0:<auth0_entity_id>:<login_slug>, for example urn:auth0:us-test-mt:okta-test-new
Configure the app in Okta
- In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
- Click Browse App Catalog.
- Search for and select the dbt Cloud app.
- Click Add Integration.
- On the General Settings tab, enter the values that you retrieved from dbt Cloud:
- Application label: Leave as the default, or rename as required.
- Auth0 URI: Enter the Auth0 URI value from dbt Cloud.
- Auth0 EntityID: Enter the Auth0 EntityID value from dbt Cloud.
- Login Slug: Enter the Login Slug value from dbt Cloud, including any prefix, for example
okta-, exactly as shown.
- Click Done.
- On the Sign On tab (or the Authentication tab in Okta Identity Engine), in the SAML Setup section, copy the following values. You need them to configure SAML in dbt Cloud:
- Identity Provider Single Sign-On URL
- Identity Provider Issuer
- X.509 Certificate
- Go to the Assignments tab and click Assign > Assign to People (or Assign to Groups).
- Select the people or groups who need access.
- Click Save and Go Back, and then click Done.
The integration doesn't work for users until you assign them to the app in Okta.
Configure SAML in dbt Cloud
- Sign in to dbt Cloud.
- Go to Account Settings > SSO & SCIM > Edit.
- On the SSO & SCIM page, paste the Identity Provider Single Sign-On URL, Identity Provider Issuer, and X.509 Certificate that you copied from Okta.
- Leave Sign SAML Auth Request disabled.
- Leave Attribute Mappings as the default
{}.
- Click Apply changes.
Supported SAML attributes
dbt Cloud supports these SAML attributes:
| Attribute |
Value |
| first_name |
user.firstName |
| last_name |
user.lastName |
| email |
user.email |
Verify SP-initiated SSO
- Go to the sign-in URL that you copied from the SSO & SCIM page. The URL looks like
https://<your-access-url>/enterprise-login/<login-slug>, for example https://testlogin/enterprise-login/okta-test-new. Your Okta sign-in page opens.
- Enter your Okta credentials. You're directed back to your dbt Cloud dashboard.