Identity and access management
Use Identity and access management to configure and understand organization SSO.
This section only applies to organizations with Okta SSO enabled.
Organizations without Okta SSO enabled can continue using the normal Mabyduck sign-in methods available to their users, such as email and connected identity providers.
Speak to support@mabyduck.com if you're interested in enabling Okta.
Okta sign in
For Okta enabled organizations, users can sign in from the Mabyduck tile in Okta or from:
https://app.mabyduck.com/org/{org-slug}/
Returning Okta-managed users who start at https://app.mabyduck.com/login are
redirected when Mabyduck can identify their organization.
This redirect works after the user has signed in through either the IdP-initiated or SP-initiated flow once.
Existing users
Each Mabyduck user can only belong to one organization.
Existing Mabyduck users keep their projects, experiments, datasets, and history when Okta is enabled for their organization.
After they join an Okta-enabled organization, the following sign-in methods no longer bypass the organization's Okta requirement:
- Email + password (including 2FA).
- Google login.
- GitHub login.
Before asking a user to sign in, confirm:
- the user is assigned to the Mabyduck app in Okta.
- the user belongs to the Mabyduck organization.
- their Okta email matches their Mabyduck email.
- they have the organization login URL or Okta tile.
App assignments
Assign the Mabyduck app in Okta to the users or groups who should sign in.
Remove the app assignment to block future sign-in.
Removing access
For Okta-enabled organizations, remove access in both systems:
- Remove the user's Mabyduck app assignment in Okta.
- Remove the user from the Mabyduck organization.
- Use Universal Logout if Okta should end active Mabyduck sessions.
Supported features
- organization Okta SSO (IdP)
- Okta dashboard tile sign-in (IdP-initiated SSO)
- organization login URL sign-in (SP-initiated SSO)
- Okta app assignment as the sign-in gate
- Just-in-Time (JIT) user creation on first valid Okta sign-in
- Universal Logout