SAML with Okta
Before you configure Okta, create your organization’s SAML connection in Kindo under Settings → SSO. You must be an organization Admin. Follow Single Sign-On (SSO) Setup and keep the ACS URL and SP Entity ID available.
Create or update the Okta application
Section titled “Create or update the Okta application”For an existing Kindo application, open it and edit its SAML settings. Skip the creation steps and continue with the SAML configuration below.
To create an application:
-
In Okta, open Applications → Applications.
-
Select Create App Integration.
-
Select SAML 2.0, then Next.
-
Enter an application name. Select Next to open Configure SAML.
Configure SAML for the application:
-
Enter these settings:
Okta field Value Single sign-on URL Kindo ACS URL Audience URI (SP Entity ID) Kindo SP Entity ID Recipient Kindo ACS URL Destination Kindo ACS URL Default RelayState Leave blank Name ID format EmailAddress Application username Email The email address must match the user’s Kindo email address on your organization’s verified domain.
-
Under Attribute Statements, add attributes with these exact names.
Name Value emailuser.emailgivenNameuser.firstNamesurnameuser.lastNameThe
emailattribute and Name ID must contain the same address. The recommendedgivenNameandsurnameattributes populate the user’s display name. -
Select Next.
-
Select I’m an Okta customer adding an internal app.
-
Select Finish.
For field details, see the Okta SAML application reference.
Add the Okta details in Kindo
Section titled “Add the Okta details in Kindo”Use metadata XML to import the IdP settings:
-
On the application’s Sign On tab in Okta, open the Metadata URL and save the page as an
.xmlfile. -
In Kindo, open Settings → SSO → Identity Provider (IdP) Configuration.
-
Select Upload metadata XML and choose the downloaded file. The file imports immediately. To use pasted XML, paste the XML contents and select Import.
-
Confirm that the certificate shows
Valid until <date>.
For manual configuration:
-
Enter these values in Identity Provider (IdP) Configuration:
Kindo field Okta value IdP Entity ID Issuer Redirect URL Sign on URL Signing certificate Full PEM contents of okta.cert, downloaded with Download on the Signing Certificate row -
Select Save. Confirm that the certificate shows
Valid until <date>.
Assign users and test
Section titled “Assign users and test”Users must be assigned to the Okta application to sign in.
-
In Okta, open Assignments and assign a pilot user or group.
-
Open Kindo in a private browser window. Select Continue with SAML SSO and enter the pilot user’s email address. Complete sign-in with Okta.
-
Test sign-in from the Kindo tile in Okta.
-
Assign the remaining users or groups after the pilot succeeds.
-
If your organization requires SSO, enable SSO Enforcement. Test a fresh sign-in with enforcement enabled.
