> For the complete documentation index, see [llms.txt](https://help.dataimporter.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.dataimporter.io/security/single-sign-on-with-okta.md).

# Single Sign-On with Okta

Follow this guide to set up Single Sign-On (SSO) in Dataimporter with Okta. This will let you control which users have access to Dataimporter, restrict access to SSO, provision new users via Just-in-Time (JIT) provisioning.

## 1. Enable SSO in Dataimporter

1. In Dataimporter, head to the Account Settings page and toggle SSO on.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FGwaco8d481FkFrx4KZD8%2Fimage.png?alt=media&amp;token=3beda87d-e525-405c-96a7-e6b18796fd4d" alt=""><figcaption></figcaption></figure>

2. In the SAML Name field enter the name as you would like it to appear e.g. <mark style="color:blue;">`Acme`</mark>
3. In the Domain field enter your corporate company name e.g. <mark style="color:blue;">`acme.com`</mark>.
4. Keep this tab open and open another tab to perform the next steps.

## 2. Add Dataimporter to Okta

1. Log in to the Okta and click on Applications

![](https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FfkjFmfpRVZGaXqgn2154%2Fimage.png?alt=media\&token=81c9c909-298a-4f9d-82b5-a48e2433563a)

2. Click on Create App Integration.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FtgFztVYTh0QHax7EAuBP%2Fimage.png?alt=media&amp;token=dd9f8807-73cf-4a02-88e4-4f9cbd297f01" alt=""><figcaption></figcaption></figure>

3. Select SAML 2.0 and click Next.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2F0Fn5EtOHnS1P1WPYqEzX%2Fimage.png?alt=media&amp;token=11aa62b1-b2d1-487c-9493-689b4fc72989" alt=""><figcaption></figcaption></figure>

4. Give the app the name <mark style="color:blue;">`DATAIMPORTER`</mark>, upload a Logo (optional), and click Next.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2F0m94O9oPhcdAfINcIDDZ%2Fimage.png?alt=media&amp;token=27949dd2-6d17-4194-9efe-88e0cefc8ceb" alt=""><figcaption></figcaption></figure>

5. In the Audience URI (SP Entity ID) field, add the value that you added in Step 2 of the Dataimporter configuration e.g. <mark style="color:blue;">`Acme`</mark>
6. In the Single sign-on URL section enter the URL in the following format https\://{instance}.dataimporter.io/saml/login/{identifier} e.g. <mark style="color:blue;">`https://app.dataimporter.io/saml/login/Acme`</mark>

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FObxfcOR9qhv4UxeZ5Wnq%2Fimage.png?alt=media&amp;token=d4053a54-f613-45c2-81a6-3f15d972d314" alt=""><figcaption></figcaption></figure>

7. Make sure you Check the box for <mark style="color:blue;">`User this for Recipient URL and Destination URL`</mark>
8. Scroll down to Attribute Statements and populate the following values.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FUp0r6tcVP1nKNf0kzwUc%2Fimage.png?alt=media&amp;token=41673956-2bb3-4838-b05c-7ddc511d8cb0" alt=""><figcaption></figcaption></figure>

9. Scroll to the bottom of the page and click <mark style="color:blue;">`Next`</mark>.
10. Under the Feedback section select the option <mark style="color:blue;">`I'm an Okta customer adding an internal app`</mark> and click the checkbox for <mark style="color:blue;">`This is an internal app that we have created`</mark>. Click <mark style="color:blue;">`Finish`</mark>.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FLKt1PH9yPJD2OOpmYObC%2Fimage.png?alt=media&amp;token=9b9d9294-8f80-4ec9-a086-79255a5fea98" alt=""><figcaption></figcaption></figure>

11. Click on <mark style="color:blue;">`Assignments`</mark> -> <mark style="color:blue;">`Assign`</mark> -> <mark style="color:blue;">`Assign to People`</mark>

12. Add any users who need access to Dataimporter.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2F4bgsGcFGb6t1zJsHy6N0%2Fimage.png?alt=media&amp;token=9c08f69b-3bfa-417d-bff6-b436541a8dc0" alt=""><figcaption></figcaption></figure>

13. Click back on the <mark style="color:blue;">`Sign On`</mark> tab and scroll down to the <mark style="color:blue;">`SAML Signing Certificates`</mark> section.
14. Click on <mark style="color:blue;">`Actions`</mark> next for the <mark style="color:blue;">`SHA-2`</mark> type, and click on <mark style="color:blue;">`Download Certificate.`</mark>
15. Click on <mark style="color:blue;">`View IdP metadata`</mark>

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FdHAUtu3Ek7vtOflUbXzu%2Fimage.png?alt=media&amp;token=b405c9b6-e161-40ae-be32-53bcc8d83f8d" alt=""><figcaption></figcaption></figure>

## 3. Configuring SSO in Dataimporter

1. Copy the <mark style="color:blue;">`entityId`</mark> value.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FCI3ttQWUpIBhc8HSWaug%2Fimage.png?alt=media&amp;token=2f52d8d9-9cca-4652-aee9-9dea32933c98" alt=""><figcaption></figcaption></figure>

2. Open the tab in Dataimporter and paste the value into the Provider Entity Id field.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FDy9WnErDan3oL7A1Zp8Y%2Fimage.png?alt=media&amp;token=8e243a6c-1dd6-4058-b60e-b39f263c2902" alt=""><figcaption></figcaption></figure>

3. Open Okta and copy the Single Sign On Location value.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FidLZTI0TOho1ksrFXEk5%2Fimage.png?alt=media&amp;token=f4c495da-a405-4068-9d3c-536cce13ddd9" alt=""><figcaption></figcaption></figure>

4. Open the tab in Dataimporter and paste the value into the Log In URL field.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2FslNWaGTztwueweYkZX8t%2Fimage.png?alt=media&amp;token=698692a8-75a6-439a-bd11-53d9fb710aff" alt=""><figcaption></figcaption></figure>

5. Open the downloaded Certificate in a text editor and copy the entire value.
6. Open the tab in Dataimporter and paste the value into the X509 Certificate field.

<figure><img src="https://2845823711-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtvRVifvxmkDBmPKpGlr2%2Fuploads%2Fve0RigYTUKJjqhcA33lt%2Fimage.png?alt=media&amp;token=506f23fd-f5b3-4a9d-8e66-8cc8606f5e00" alt=""><figcaption></figcaption></figure>

7. Click on Save.
8. Contact Dataimporter Support to validate and enable SSO for your Organization.&#x20;
