Add Okta as an identity provider
Use Okta to give your organization users single sign-on (SSO) access to Aiven using SAML. Aiven also supports user provisioning for Okta with SCIM.
Supported features
- Identity provider (IdP) initiated SSO
- Service provider (SP) initiated SSO
For more information on the listed features, visit the Okta Glossary.
Step 1: Add the IdP in the Aiven Console
- In the organization, click Admin.
- Click Identity providers .
- Click Add identity provider.
- Select an identity provider and enter a name.
- Select a verified domain to link this IdP to. Users see linked IdPs on the login page.
On the Configuration step are two parameters that you use to set up the SAML authentication in your IdP:
- Metadata URL
- ACS URL
Step 2: Configure SAML on Okta
- In the Okta administrator console, go to Applications > Applications.
- Click Browse App Catalog.
- Search for and open the Aiven app.
- Click Add Integration and Done.
- On the Sign On tab, click Edit.
- In the Advanced Sign-on Settings set the Metadata URL and ACS URL to the URLs copied from the Aiven Console.
- Set the Default Relay State for the console you use:
- For the Aiven Console: https://console.aiven.io
- For the Aiven GCP Marketplace Console: https://console.gcp.aiven.io/
- For the Aiven AWS Marketplace Console: https://console.aws.aiven.io/
- Click Save.
- In the SAML 2.0 section, click More details.
- Copy the Sign on URL, Issuer, and the Signing Certificate. You'll use these to configure the IdP in Aiven.