Explore documentation
Okta SAML setup instructions
Connect your Okta organization with Better Stack to enable single sign-on (SSO) for you and your colleagues.
Supported features
- IdP-initiated SSO
- SP-initiated SSO
- Just-in-Time provisioning
Configuration steps
In Better Stack
- Go to Single Sign-On settings and click Connect in the Okta SSO section.
- Copy the Integration ID. You will need it in a moment.
In Okta
- Sign in to your Okta organization.
- Go to Applications → Applications.
- Click Browse App Catalog and search for Better Stack.
- Click Add integration, then Done to create the integration.
- Go to the Sign on tab and click Edit next to Settings.
- Scroll to Advanced Sign-on Settings and enter the Integration ID from Better Stack.
- Click Save.
- In the Assignments tab, assign your user account to the Better Stack application. You won't be able to finish the setup otherwise.
- Return to the Sign on tab.
- Go to SAML Signing Certificates, open the dropdown for the SHA-2 certificate, and click View IdP Metadata.
- Copy the metadata link.
In Better Stack
- Paste the metadata link into the corresponding field in your Better Stack SSO settings. Alternatively, you can enter the Identity Provider Single Sign-On URL and X.509 Certificate manually.
- Click Connect. You will be redirected to Okta to sign in.
Your Single Sign-On is now configured. 🎉
Optional: Just-in-time provisioning (JIT)
- Go to Teams.
- Click the three dots on the desired team and select Configure.
- Add your email domain to Pre-approved domains.
- Click Save changes.
Optional: SP-initiated SSO
The Okta Single Sign-On URL is available in your Single Sign-On settings under Sign in URL.
The URL can also be constructed as follows:
https://betterstack.com/users/sign-in/sso/okta/[integrationId]