Skip to content

SAML with Okta

Before you configure Okta, create your organization’s SAML connection in Kindo under Settings → SSO. You must be an organization Admin. Follow Single Sign-On (SSO) Setup and keep the ACS URL and SP Entity ID available.

For an existing Kindo application, open it and edit its SAML settings. Skip the creation steps and continue with the SAML configuration below.

To create an application:

  1. In Okta, open Applications → Applications.

  2. Select Create App Integration.

  3. Select SAML 2.0, then Next.

  4. Enter an application name. Select Next to open Configure SAML.

Configure SAML for the application:

  1. Enter these settings:

    Okta fieldValue
    Single sign-on URLKindo ACS URL
    Audience URI (SP Entity ID)Kindo SP Entity ID
    RecipientKindo ACS URL
    DestinationKindo ACS URL
    Default RelayStateLeave blank
    Name ID formatEmailAddress
    Application usernameEmail

    The email address must match the user’s Kindo email address on your organization’s verified domain.

  2. Under Attribute Statements, add attributes with these exact names.

    NameValue
    emailuser.email
    givenNameuser.firstName
    surnameuser.lastName

    The email attribute and Name ID must contain the same address. The recommended givenName and surname attributes populate the user’s display name.

  3. Select Next.

  4. Select I’m an Okta customer adding an internal app.

  5. Select Finish.

For field details, see the Okta SAML application reference.

Use metadata XML to import the IdP settings:

  1. On the application’s Sign On tab in Okta, open the Metadata URL and save the page as an .xml file.

  2. In Kindo, open Settings → SSO → Identity Provider (IdP) Configuration.

  3. Select Upload metadata XML and choose the downloaded file. The file imports immediately. To use pasted XML, paste the XML contents and select Import.

  4. Confirm that the certificate shows Valid until <date>.

For manual configuration:

  1. Enter these values in Identity Provider (IdP) Configuration:

    Kindo fieldOkta value
    IdP Entity IDIssuer
    Redirect URLSign on URL
    Signing certificateFull PEM contents of okta.cert, downloaded with Download on the Signing Certificate row
  2. Select Save. Confirm that the certificate shows Valid until <date>.

Users must be assigned to the Okta application to sign in.

  1. In Okta, open Assignments and assign a pilot user or group.

  2. Open Kindo in a private browser window. Select Continue with SAML SSO and enter the pilot user’s email address. Complete sign-in with Okta.

  3. Test sign-in from the Kindo tile in Okta.

  4. Assign the remaining users or groups after the pilot succeeds.

  5. If your organization requires SSO, enable SSO Enforcement. Test a fresh sign-in with enforcement enabled.