{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["img"]},"type":"markdown"},"seo":{"title":"Configure Okta OIDC SSO","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"configure-okta-oidc-sso","__idx":0},"children":["Configure Okta OIDC SSO"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this guide to configure the Mabyduck OpenID Connect integration in Okta."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This guide only applies to organizations with Okta SSO enabled."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Organizations without Okta SSO enabled can continue using the normal Mabyduck"," ","sign-in methods available to their users, such as email and connected identity"," ","providers."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"getting-started","__idx":1},"children":["Getting started"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To enabled Okta for your Mabyduck organization, contact"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"mailto:support@mabyduck.com"},"children":["support@mabyduck.com"]}," to start."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Please include the slug you'd like to have for your organization login URL, for"," ","example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["acme"]}," if you want ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/org/acme/"]}," to be your"," ","organization login URL."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":2},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you configure the integration, confirm that you have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["an Okta admin account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["a Mabyduck organization owner or admin account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Okta SSO enabled for your Mabyduck organization."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["your Mabyduck organization login slug, for example ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["acme"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["your Mabyduck Okta issuer URL."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["your Mabyduck domain, which defaults to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["app.mabyduck.com"]}," unless Mabyduck has"," ","configured you a custom domain."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the Okta organization issuer URL for this integration:"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://{your-company}.okta.com"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Do not use:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the Okta admin URL."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["a custom authorization server URL, such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/oauth2/default"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["a dev, staging, localhost, preview, or internal test URL."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"supported-features","__idx":3},"children":["Supported features"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Mabyduck supports:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SP-initiated SSO:"]}," users start from Mabyduck and are redirected to Okta."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["IdP-initiated SSO:"]}," users start from the Mabyduck tile in Okta."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Just-in-Time user creation:"]}," Mabyduck can create a user after a valid Okta"," ","sign-in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Universal Logout:"]}," Okta can end active Mabyduck sessions through global"," ","token revocation."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Mabyduck does not support:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["SCIM provisioning."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["refresh tokens."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["custom OIDC scopes."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["SP-initiated Single Logout."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["OIDC Post Logout URI."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information about Universal Logout, see"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/account-and-settings/iam/universal-logout"},"children":["Universal Logout"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"configuration-steps","__idx":4},"children":["Configuration steps"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"add-the-mabyduck-app-in-okta","__idx":5},"children":["Add the Mabyduck app in Okta"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to your Okta Admin Console."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Applications"]}," -> ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Applications"]}," -> ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Browse App Catalog"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Search for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Mabyduck"]}," in the catalog."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click on Add integration."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter the organization slug and Mabyduck domain above."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Assign the app to the users or groups who should sign in to Mabyduck."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Users cannot complete Okta sign-in until they are assigned to the Mabyduck app."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"urls","__idx":6},"children":["URLs"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You may see this URLs within your apps logs, the URLs are expected to match"," ","exactly. They are useful references if you are debugging the integration."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Replace ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{org-slug}"]}," with your Mabyduck organization login slug."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Okta field"},"children":["Okta field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Sign-in redirect URIs"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/oauth2/okta/{org-slug}/auth/"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/oauth2/okta/{org-slug}/connect/"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Initiate login URI"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/org/{org-slug}/"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Sign-in URI"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/org/{org-slug}/"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Global token revocation endpoint"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/oauth2/okta/{org-slug}/revoke/"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"optional-configure-universal-logout","__idx":7},"children":["Optional: configure Universal Logout"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you enable Universal Logout in Okta, configure the Mabyduck app integration:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Log in to your Okta Admin Console."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Applications"]}," -> ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Applications"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select the Mabyduck app integration."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Open the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Authentication"]}," tab."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Logout"]}," section, click ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Edit"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Okta system or admin initiates logout"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Set the global token revocation endpoint to:"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/oauth2/okta/{org-slug}/revoke/"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["authentication method: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SIGNED_JWT"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["subject format: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Issuer and Subject identifier"]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Save"]},"."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Replace ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{org-slug}"]}," with your Mabyduck organization login slug."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/account-and-settings/iam/universal-logout"},"children":["Universal Logout"]}," for the full setup guide."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"idp-initiated-sso","__idx":8},"children":["IdP-initiated SSO"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Users can start sign-in from the Mabyduck tile in their Okta dashboard."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open the Okta End-User Dashboard."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the Mabyduck tile."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm you are redirected to Mabyduck and signed in."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"sp-initiated-sso","__idx":9},"children":["SP-initiated SSO"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Users can start sign-in from Mabyduck."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/org/{org-slug}/"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter your email address."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Continue with Okta"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Complete Okta sign-in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm you are returned to Mabyduck."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Returning Okta-managed users can also start from the standard Mabyduck login"," ","page:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/login/"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter your email address."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm Mabyduck redirects you to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://app.mabyduck.com/org/{org-slug}/"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Complete Okta sign-in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm you are returned to Mabyduck."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["SP-initiated sign-in requires an existing Mabyduck user who belongs to your"," ","Okta-enabled organization."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"configuring-mabyduck","__idx":10},"children":["Configuring Mabyduck"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To configure Okta SSO in Mabyduck, you must be an organization owner or admin."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Follow these steps:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On the home page, make sure you're currently on a Organization, then click on"," ","the organization icon in the top right corner. ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/organization_user_home.8d465f3d58c2397c9abe0eae3112059266007f964a1ff4f88a6eaadb0974ef57.1b1a2ba1.png","alt":"Mabyduck user home","framed":false,"withLightbox":false,"width":"80%","align":"center"},"children":[]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Organization"]}," in the sidebar menu, select Organization, enter your"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["name"]}," and a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["logo"]},", then click on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Save"]},". ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/organization_user_organization.c46ecbfa1d2802915d2a42fbeba6a1517e0441b29abd38fdb8a09302611fccf7.1b1a2ba1.png","alt":"Mabyduck organization settings name and logo","framed":false,"withLightbox":false,"width":"80%","align":"center"},"children":[]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SSO"]}," in the left sidebar menu, select ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["enable SSO"]},", enter your Okta"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["issuer URL"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client ID"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client secret"]},", then click on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Save"]},"."]}]}]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/organization_user_sso.cb0e03df4ed14cad3f0f5236124c216bfa905e6383c9df4b0d5967a95f00179d.1b1a2ba1.png","alt":"Mabyduck organization settings SSO","framed":false,"withLightbox":false,"width":"80%","align":"center"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"token-and-session-behavior","__idx":11},"children":["Token and session behavior"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Okta OIN OIDC integrations use the Okta organization authorization server. Okta"," ","access tokens and ID tokens expire after one hour."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Mabyduck uses the Okta access token only during sign-in. It does not store or"," ","refresh the Okta access token after the login exchange."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After sign-in, Mabyduck maintains its own application session. Mabyduck"," ","application sessions expire after two weeks by default."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"oidc-limitations","__idx":12},"children":["OIDC limitations"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["OIDC SSO integrations published in the OIN have these limitations:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The integration must use the Okta organization authorization server."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Refresh tokens are not supported."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["offline_access"]}," scope is not available."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Custom scopes, such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["groups"]},", are not supported."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"troubleshoot","__idx":13},"children":["Troubleshoot"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"okta-rejects-sign-in","__idx":14},"children":["Okta rejects sign-in"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Check that:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the sign-in redirect URI matches exactly."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the URI includes the trailing slash."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["only customer-facing production URLs are configured."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the user is assigned to the Mabyduck app in Okta."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the issuer URL in Mabyduck matches the Okta app."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["the client ID and client secret in Mabyduck match the Okta app."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"password-google-or-github-sign-in-does-not-work","__idx":15},"children":["Password, Google, or GitHub sign-in does not work"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This is expected for users in an Okta-enabled organization. Okta is the required"," ","sign-in method for those users."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Organizations without Okta SSO enabled can continue using normal Mabyduck"," ","sign-in methods."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"contact-support","__idx":16},"children":["Contact support"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Include:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Okta issuer URL."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Mabyduck organization slug."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["affected user email address."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["exact error message."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["whether the issue happens from the Okta tile, the Mabyduck login page, or"," ","both."]}]}]},"headings":[{"value":"Configure Okta OIDC SSO","id":"configure-okta-oidc-sso","depth":1},{"value":"Getting started","id":"getting-started","depth":2},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"Supported features","id":"supported-features","depth":2},{"value":"Configuration steps","id":"configuration-steps","depth":3},{"value":"Add the Mabyduck app in Okta","id":"add-the-mabyduck-app-in-okta","depth":4},{"value":"URLs","id":"urls","depth":3},{"value":"Optional: configure Universal Logout","id":"optional-configure-universal-logout","depth":4},{"value":"IdP-initiated SSO","id":"idp-initiated-sso","depth":3},{"value":"SP-initiated SSO","id":"sp-initiated-sso","depth":3},{"value":"Configuring Mabyduck","id":"configuring-mabyduck","depth":3},{"value":"Token and session behavior","id":"token-and-session-behavior","depth":2},{"value":"OIDC limitations","id":"oidc-limitations","depth":2},{"value":"Troubleshoot","id":"troubleshoot","depth":2},{"value":"Okta rejects sign-in","id":"okta-rejects-sign-in","depth":3},{"value":"Password, Google, or GitHub sign-in does not work","id":"password-google-or-github-sign-in-does-not-work","depth":3},{"value":"Contact support","id":"contact-support","depth":3}],"frontmatter":{"seo":{"title":"Configure Okta OIDC SSO"}},"lastModified":"2026-06-10T13:53:41.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/account-and-settings/iam/okta","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}