Read this before you enable SAML
Enabling SAML will affect all users who use this application, which means that users will not be able to sign in through their regular sign-in page. They will be able to access the app through the Okta service.
Backup URL
RudderStack doesn't provide a backup sign-in URL where users can sign in using their regular username and password. You can contact RudderStack Support (hello@rudderstack.com) to turn off SAML, if necessary.
The Okta/RudderStack SAML integration currently supports the following features:
For more information on the listed features, visit the Okta Glossary.
Contact the RudderStack Support team at hello@rudderstack.com and request that they enable SAML 2.0 for your account.
Include the following information with your request:
Identity Provider Single Sign-On URL: Copy and paste the following:
Sign into the Okta Admin Dashboard to generate this variable.
Identity Provider Issuer: Copy and paste the following:
Sign into the Okta Admin Dashboard to generate this variable.
X.509 Certificate: Copy and paste the following:
Sign into the Okta Admin Dashboard to generate this variable.
The RudderStack Support team will process your request and provide you with the Login URL value.
Assign your user to the app.
Since the application only supports an SP-initiated flow, you can simulate an IDP-initiated flow with the Bookmark sign-on method. In Okta add another RudderStack app and follow the steps below:
SIGN ON METHODS: Select Bookmark-only.
Enter your Login URL (step 3) into the corresponding field.
Click Save.
Assign your user to the app with the bookmark mode.
In Okta, select the General tab of your first RudderStack app, then click Edit.
Check Do not display application icon to users.
click Save.
Done!
The following SAML attributes are supported:
Name | Value |
---|---|
FirstName | user.firstName |
LastName | user.lastName |
user.email |
Since only SP-initiated flow is supported, we recommend hiding the application icon for users.
Enter your email address, then click SIGN IN.