Okta

As a Capacity Admin user, you can configure SAML 2.0 single sign-on (SSO) using Okta as your identity provider. This article walks you through configuring Okta as your identity provider (IdP), what to share with Capacity to complete setup, and what your users will see once SSO is enabled.


How it Works

In this configuration, Capacity is the service provider (SP) and Okta is the identity provider (IdP). You'll create a new SAML application in Okta, configure it with the SAML values Capacity requires, and then share your IdP metadata with Capacity so we can complete the connection on our end.


Before you Begin

Before you can configure SAML 2.0 SSO in Okta, you'll need:

  • An admin account within your CI environment.
  • A full admin user within Okta to create and configure SSO applications.

Configure Okta

Add SAML Application

  • Sign in to your Okta Admin Console.
  • Go to Applications >> Applications.
  • Select Create App Integration.
  • Choose SAML 2.0 as the sign-in method, then select Next.
  • On the General Settings tab, enter an App name (we recommend Capacity Conversation Intelligence)
    • Optional - upload a logo (you can request this from Capacity, or choose your own)
  • Select Next.
  • On the Configure SAML tab, enter the values below (replacing the placeholder with your own Capacity environment URL — the same one you use to sign in day to day).
FieldValue
Single sign-on URLhttps://{your-environment-url}/AuthServices/Acs
Audience URI (SP Entity ID)https://{your-environment-url}/AuthServices
  • Under Attribute Statements, add an attribute with Nameuser.id and Valueuser.login.
  • Continue through the remaining setup screens. On the Feedback step, select I'm an Okta customer adding an internal app, then select Finish.

Download Metadata

On the application's Sign On tab, select View SAML setup instructions. Copy the contents of the Identity Provider metadata field and save it securely. This tells Capacity how to communicate with your Okta org and request authentication.

Assign Users

On the application's Assignments tab, assign everyone who should sign in to Capacity using SSO.


Account Activation and Sign-In Experience

When a Capacity user needs to be activated and they're using SSO, they should use the Sign in with...  button rather than the Activate account button. Once SSO is enabled for your organization, your users' login page will include this option alongside standard sign-in.

What to Share with Capacity

ItemDescription
IdP metadataThe Identity Provider metadata copied in step Download Metadata.
Sign-in button label preference (Optional)Defaults to "Sign in with Okta" unless you request otherwise.



Was this article helpful?