> For the complete documentation index, see [llms.txt](https://docs.veedna.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veedna.com/getting-started/create-an-account/configure-okta-for-sso.md).

# Configure Okta for SSO

Configure SAML single sign-on with Okta.

## Configure Okta for SSO

Create a SAML application in Okta. Then add its identity provider details to Lineaje.

### Before you begin

Collect these values from the Lineaje SSO configuration:

* Entity ID
* Post callback URL

You need Tenant Admin access in Lineaje. You also need permission to create Okta applications.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FdIAoYSmmUax53KVoCy0D%2Fimage.png?alt=media&amp;token=87b7c0b8-eaa4-4c8d-8b2a-a475d98c9765" alt="" width="563"><figcaption></figcaption></figure>

### Create an application in Okta

1. Open the Okta portal and switch to **Admin** mode.
2. Select **Applications** → **Applications**.
3. Select **Create App Integration**.
4. Select **SAML 2.0**, then select **Next**.
5. Enter an application name.
6. Select **Next**.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FA2038TKUiIphTlv4nFK1%2Fimage.png?alt=media&amp;token=4a7673b9-3111-44b2-9fd9-d7b08a61b781" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FjQledJoN3dQaZEhleu6X%2Fimage.png?alt=media&amp;token=1d62dfc9-b26d-4984-a9c1-93aba71e8a82" alt="" width="563"><figcaption></figcaption></figure>

### Configure SAML in Okta

1. Enter the Lineaje values in the SAML configuration:

   ```
   Audience URI (SP Entity ID) -> Lineaje Entity ID

   Single sign-on URL -> Lineaje post callback URL
   ```
2. Set **Name ID format** to **EmailAddress**.
3. Configure the required attribute statements. Okta includes these attributes in the SAML assertion.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FRA6nIlchfCzo48EjjENJ%2Fimage.png?alt=media&amp;token=b45c5d20-e364-41f6-90fa-e5b85a50096e" alt="" width="547"><figcaption></figcaption></figure>

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2Fe0HH0S00OQ1PPKKjEnNY%2Fimage.png?alt=media&amp;token=6731e5df-c4b0-4277-bb9b-e3bc941cf434" alt="" width="563"><figcaption></figcaption></figure>

4. Complete the remaining Okta prompts and select **Finish**.

Okta screens vary by version. The following examples show common options.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FZhiEggX2ZYfIxrtJ9MPg%2Fimage.png?alt=media&amp;token=a47b328a-e789-428c-9ffe-37b8da4a1c3a" alt="" width="557"><figcaption></figcaption></figure>

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FOBvAdkBe6CQJpnvSdTAC%2Fimage.png?alt=media&amp;token=7c78addf-84d0-4afc-9246-7f5085041002" alt="" width="563"><figcaption></figcaption></figure>

### Assign users and groups

1. Open the application's **Assignments** tab.
2. Assign the users or groups that can access Lineaje.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FxSH3uSPnrG4vFj1AK9nz%2Fimage.png?alt=media&amp;token=8714a955-b511-4832-a28e-7505aeb4fe2d" alt="" width="563"><figcaption></figcaption></figure>

### Collect Okta SAML details

1. Open the application's **Sign On** tab.
2. Select **View SAML setup instructions**.
3. Copy the identity provider single sign-on URL.
4. Download the X.509 certificate.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2F5T91FpzWkP8biRYbhpEF%2Fimage.png?alt=media&amp;token=ab8f24e5-b93d-4eba-afb9-1cf16e7745c7" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FNMaPpmjODVQHM6FZQQKX%2Fimage.png?alt=media&amp;token=1aee284d-b427-470c-9fc4-f70b3997b218" alt="" width="563"><figcaption></figcaption></figure>

### Configure SAML in Lineaje

1. Return to the Lineaje application.
2. Open **Settings** → **Authentication**.
3. Select **Edit Configuration** → **Single Sign-On**.
4. Enter the Okta identity provider single sign-on URL in **Sign-in URL**.
5. Upload the X.509 certificate that you downloaded from Okta.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FkfwvigXJARu9ZmEi5UdL%2Fimage.png?alt=media&amp;token=3b3f0707-a074-4d92-ba39-fb0e6f5c67be" alt="" width="563"><figcaption></figcaption></figure>

6. Select **Enable SSO**.

<figure><img src="https://2983949833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzRZpxg1UUX5iPuJAfelm%2Fuploads%2FMR6dUNab97ccDdjf4JFE%2Fimage.png?alt=media&amp;token=f19ce48c-a3d6-4151-a902-1312a19d7b7a" alt="" width="540"><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veedna.com/getting-started/create-an-account/configure-okta-for-sso.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
