Okta single-sign-on for Ortto

Overview

App authentication settings in Ortto allow you to control how users sign in to their accounts. Okta Single-Sign-On enforced forces all users to login with their Okta account. This also requires additional setup in OKTA.

NOTE: Okta Single-Sign-On is only available to Enterprise customers.

There are two main components to configuring Okta single-sign-on for Ortto:


Add and configure the Ortto app in Okta

In Okta, create a custom OIDC Web Application for Ortto.

  1. Add both of these URLs as sign-in redirect URIs:
    1. https://accounts-api-us.ortto.app/-/okta/auth
    2. https://accounts-api-us.ortto.app/-/signup/okta/auth
  2. Assign the app to any user(s) with an Ortto account. Their Okta email and Ortto email need to match exactly.
  3. Note the app's Client ID and Client secret. You'll need them when you configure the Okta connection in Ortto.

Configure the Okta connection

To set up Okta Single Sign-On (SSO) for Ortto, follow these steps:

  1. After adding and configuring the Ortto app in Okta, go to Ortto's Settings > Privacy, Security & GDPR > App authentication.
  2. Choose Okta Single-Sign-On enforced (requires additional setup in Okta).
  3. Click Save and provide Okta details in the dialog that appears, including Okta domain, Client ID, and Client secret.
  4. Click Submit.
  5. Sign out, then sign in using https://ortto.app/login?okta-domain=<your-okta-domain>&instance_id=<yourorttoid>

NOTE:

  • To allow additional Ortto users to sign in, ensure they have corresponding user accounts with matching email addresses configured in your Okta domain.
    • Assign the Ortto app to these users in Okta.
  • Permissions assigned to a user in Ortto are separate from those in Okta. Ortto user permissions dictate access within Ortto.
  • If you add new user accounts in Ortto after configuring them in Okta, these users will receive an email invitation to sign up or sign in to Ortto via Okta.