Okta

Configure SAML 2.0 for dbt Cloud

This guide provides instructions on configuring SAML 2.0 Single Sign-On (SSO) for the dbt Cloud app integration.

Contents


Supported features

dbt Cloud supports the following features:

Prerequisites

Integrate the app in Okta

Retrieve your account-specific values from dbt Cloud

  1. Sign in to dbt Cloud.
  2. Go to Account Settings > SSO & SCIM, select Edit, and then select Okta as your IdP.
  3. In Identity provider values, note the Auth0 URI, Auth0 EntityID, and Login Slug values. You need them to complete the configuration in Okta.

    Save the sign-in URL that's displayed on this page. You need it later to verify SSO.

dbt Cloud displays your Single sign-on URL and Audience URI (SP Entity ID) on this screen, based on those values:

Configure the app in Okta

  1. In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
  2. Click Browse App Catalog.
  3. Search for and select the dbt Cloud app.
  4. Click Add Integration.
  5. On the General Settings tab, enter the values that you retrieved from dbt Cloud:
    • Application label: Leave as the default, or rename as required.
    • Auth0 URI: Enter the Auth0 URI value from dbt Cloud.
    • Auth0 EntityID: Enter the Auth0 EntityID value from dbt Cloud.
    • Login Slug: Enter the Login Slug value from dbt Cloud, including any prefix, for example okta-, exactly as shown.
  6. Click Done.
  7. On the Sign On tab (or the Authentication tab in Okta Identity Engine), in the SAML Setup section, copy the following values. You need them to configure SAML in dbt Cloud:
    • Identity Provider Single Sign-On URL
    • Identity Provider Issuer
    • X.509 Certificate
  8. Go to the Assignments tab and click Assign > Assign to People (or Assign to Groups).
  9. Select the people or groups who need access.
  10. Click Save and Go Back, and then click Done.

    The integration doesn't work for users until you assign them to the app in Okta.

Configure SAML in dbt Cloud

  1. Sign in to dbt Cloud.
  2. Go to Account Settings > SSO & SCIM > Edit.
  3. On the SSO & SCIM page, paste the Identity Provider Single Sign-On URL, Identity Provider Issuer, and X.509 Certificate that you copied from Okta.
  4. Leave Sign SAML Auth Request disabled.
  5. Leave Attribute Mappings as the default {}.
  6. Click Apply changes.

Supported SAML attributes

dbt Cloud supports these SAML attributes:

Attribute Value
first_name user.firstName
last_name user.lastName
email user.email

Verify SP-initiated SSO

  1. Go to the sign-in URL that you copied from the SSO & SCIM page. The URL looks like https://<your-access-url>/enterprise-login/<login-slug>, for example https://testlogin/enterprise-login/okta-test-new. Your Okta sign-in page opens.
  2. Enter your Okta credentials. You're directed back to your dbt Cloud dashboard.