Okta single-sign-on for Ortto
Overview
App authentication settings in Ortto allow you to control how users sign in to their accounts. Okta Single-Sign-On enforced forces all users to login with their Okta account. This also requires additional setup in OKTA.
NOTE: Okta Single-Sign-On is only available to Enterprise customers.
There are two main components to configuring Okta single-sign-on for Ortto:
Add and configure the Ortto app in Okta
In Okta, create a custom OIDC Web Application for Ortto.
- Add both of these URLs as sign-in redirect URIs:
https://accounts-api-us.ortto.app/-/okta/authhttps://accounts-api-us.ortto.app/-/signup/okta/auth
- Assign the app to any user(s) with an Ortto account. Their Okta email and Ortto email need to match exactly.
- Note the app's Client ID and Client secret. You'll need them when you configure the Okta connection in Ortto.
Configure the Okta connection
To set up Okta Single Sign-On (SSO) for Ortto, follow these steps:
- After adding and configuring the Ortto app in Okta, go to Ortto's Settings > Privacy, Security & GDPR > App authentication.
- Choose Okta Single-Sign-On enforced (requires additional setup in Okta).
- Click Save and provide Okta details in the dialog that appears, including Okta domain, Client ID, and Client secret.
- Click Submit.
- Sign out, then sign in using
https://ortto.app/login?okta-domain=<your-okta-domain>&instance_id=<yourorttoid>
NOTE:
- To allow additional Ortto users to sign in, ensure they have corresponding user accounts with matching email addresses configured in your Okta domain.
- Assign the Ortto app to these users in Okta.
- Permissions assigned to a user in Ortto are separate from those in Okta. Ortto user permissions dictate access within Ortto.
- If you add new user accounts in Ortto after configuring them in Okta, these users will receive an email invitation to sign up or sign in to Ortto via Okta.