{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Okta SSO (SAML)","description":"Control the power of AI Agents in runtime.","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"okta-sso-saml","__idx":0},"children":["Okta SSO (SAML)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Let your team sign in to the Capsule portal with their Okta credentials using SAML 2.0 single sign-on."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"overview","__idx":1},"children":["Overview"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Okta SSO lets your users authenticate to Capsule through your existing Okta org instead of an email magic link. Okta acts as the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML identity provider (IdP)"]},"; Capsule uses ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Auth0"]}," as its identity broker (the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["service provider, SP"]},") and accepts the SAML assertion Okta issues at sign-in."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["This is not the same as the Okta integration."]}," The ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/okta"},"children":["Okta integration"]}," is a directory sync that ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["enriches user profiles"]}," with group and attribute data. Okta SSO governs ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["how people log in"]}," to Capsule Portal. The two are independent - you can enable either, both, or neither."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You configure SSO yourself from ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Single Sign On"]}," in the Capsule portal. Setup is a round trip with Okta: create a SAML app in Okta, paste Okta's sign-in URL and certificate into Capsule, then copy the SP values Capsule generates back into Okta."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-it-works","__idx":2},"children":["How It Works"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A user opens the Capsule login page and enters their work email."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Capsule matches the email domain to your Okta connection and redirects the browser to Okta."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The user authenticates with Okta (password, MFA, or whatever policies your org enforces)."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Okta posts a signed SAML assertion back to Capsule's ACS URL."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Capsule validates the assertion and signs the user in, provisioning the account on first login."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If the account e-mail already exists in Capsule, it will be linked with the Okta one."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":3},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you begin, ensure you have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Owner"]}," role in Capsule - only Owners can manage settings and open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single Sign On"]}," tab. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/user-roles"},"children":["User Roles & Permissions"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["An ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta admin"]}," role that can create and assign SAML app integrations"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["verified email domain"]}," your users sign in with (e.g., ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["your-company.com"]},")"]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"setup-overview","__idx":4},"children":["Setup Overview"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Setup is a round trip between the Okta Admin Console and the Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single Sign On"]}," settings:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create a SAML app"]}," in Okta (with placeholder URLs for now)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configure the connection"]}," in Capsule - paste Okta's sign-in URL and certificate, set your domains, then copy the SP values Capsule generates"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Copy Capsule's SP values"]}," back into the Okta app"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assign users"]}," and test"]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-1-create-a-saml-app-integration-in-okta","__idx":5},"children":["Step 1: Create a SAML App Integration in Okta"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create the Okta app first to obtain its IdP sign-in URL and signing certificate. Capsule generates its SP values only after the connection is saved (Step 2), so enter ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["temporary placeholder URLs"]}," here - you'll replace them in Step 3."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sign in to your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta Admin Console"]}," as an admin."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Applications"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Applications"]},", then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create App Integration"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML 2.0"]}," as the sign-in method, then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["General Settings"]},", give the app a name (e.g., ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Capsule Security"]},"), optionally add a logo, then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configure SAML"]},", enter temporary placeholders (you'll update these in Step 3):"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single sign-on URL"]}," - a placeholder such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://example.com/placeholder"]},". Leave ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Use this for Recipient URL and Destination URL"]}," checked."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Audience URI (SP Entity ID)"]}," - a placeholder such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://example.com/placeholder"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name ID format"]}," - select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["EmailAddress"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application username format"]}," - select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Email"]},"."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},", choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["I'm an Okta customer adding an internal app"]},", then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Finish"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sign On"]}," tab you'll find ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Attribute Statements"]}," section, add the following so Capsule receives the user's identity and profile. Use the exact names:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Name"},"children":["Name"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Expression"},"children":["Expression"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["user.profile.email"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["given_name"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["user.profile.firstName"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["family_name"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["user.profile.lastName"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Only ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email"]}," is required; the name attributes populate the user's display name in Capsule."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On the new app's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sign On"]}," tab, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["More details"]}," under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML 2.0"]}," and copy both of the following - you'll enter them in Capsule in Step 2:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sign on URL"]}," - e.g., ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<your-org>.okta.com/app/<app-id>/sso/saml"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Signing Certificate"]}," - download or copy the signing certificate (make sure it ends with the following extensions: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".pem"]}," / ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".crt"]}," / ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".cer"]},")"]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-2-configure-the-connection-in-capsule","__idx":6},"children":["Step 2: Configure the Connection in Capsule"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Enter Okta's IdP details in the Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single Sign On"]}," settings, then read back the SP values Capsule generates."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Sign in to the Capsule portal as an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Owner"]}," and go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Single Sign On"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Turn on ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enable SAML SSO configuration"]},". SAML is the supported protocol; others are coming soon."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fill in the fields:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorized Domains"]}," - the email domain(s) that should use this connection (e.g., ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["your-company.com"]},"). Capsule routes sign-ins from these domains to Okta."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sign In Endpoint"]}," - paste the Okta ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identity Provider Single Sign-On URL"]}," from Step 1."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SSL/TLS Certificate"]}," - upload the Okta ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["X.509 certificate"]}," from Step 1 (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".crt"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".cer"]},"). Capsule uses it to verify Okta's SAML signature."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After saving, the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identity Provider Configuration"]}," section appears with two values Okta needs. Keep this page open for Step 3:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identifier (Entity ID)"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Reply URL (ACS URL)"]}]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-3-copy-capsules-sp-values-back-into-okta","__idx":7},"children":["Step 3: Copy Capsule's SP Values Back into Okta"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Replace the Step 1 placeholders with the real values Capsule generated."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"steps","__idx":8},"children":["Steps"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Okta, open the app → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["General"]}," tab → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML Settings"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]},", and continue to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configure SAML"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Update the two URLs:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single sign-on URL"]}," - paste the Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Reply URL (ACS URL)"]},". Leave ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Use this for Recipient URL and Destination URL"]}," checked."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Audience URI (SP Entity ID)"]}," - paste the Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identifier (Entity ID)"]},"."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},", then ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Finish"]}," to save."]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-4-assign-users-and-test","__idx":9},"children":["Step 4: Assign Users and Test"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"assign-access-in-okta","__idx":10},"children":["Assign access in Okta"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the app's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assignments"]}," tab, assign the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["people"]}," or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["groups"]}," who should be able to sign in to Capsule."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Users who aren't assigned the app in Okta cannot complete SSO."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"test-the-connection","__idx":11},"children":["Test the connection"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Capsule SSO is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["service-provider-initiated"]}," - users start from Capsule, not from the Okta dashboard:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to the Capsule login page, enter a work email on an authorized domain, and confirm you're redirected to Okta and back into Capsule."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On first successful login, Capsule links the user's account automatically to existing Capsule users."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Capsule does not support IdP-initiated sign-in, so the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Capsule Security"]}," tile on the Okta dashboard won't complete a login. To avoid confusion, hide the app icon in Okta (",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["General"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["App Visibility"]}," → uncheck ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Display application icon to users"]},")."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"attribute-mapping","__idx":12},"children":["Attribute Mapping"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Okta attribute statement"},"children":["Okta attribute statement"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Maps to in Capsule"},"children":["Maps to in Capsule"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Required"},"children":["Required"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User identity (unique ID)"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Yes"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["given_name"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["First name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["No"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["family_name"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Last name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["No"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email"]}," is the stable identifier Capsule keys the account on, so make sure the Okta ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name ID"]}," is the user's email and stays consistent."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"scim-provisioning-optional","__idx":13},"children":["SCIM Provisioning (Optional)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["With SSO alone, Capsule creates accounts ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["just-in-time"]}," - a user exists in Capsule only after their first successful login. SCIM (System for Cross-domain Identity Management) upgrades this to full lifecycle management driven by Okta:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]}," - users assigned to the Okta app are provisioned in Capsule before they ever sign in"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Update"]}," - profile changes in Okta (name, email) sync to Capsule automatically"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Deactivate"]}," - unassigning or deactivating a user in Okta deactivates their Capsule account"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Group push"]}," - Okta groups sync to Capsule, where you can map them to Capsule roles"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Capsule supports ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["inbound SCIM 2.0"]}," on top of the SAML connection you configured above - Okta pushes changes to a SCIM endpoint Capsule hosts; nothing flows back into Okta. Authentication uses bearer tokens you generate and revoke in the Capsule portal. SCIM does not change how users sign in - login still happens through SAML SSO."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"prerequisites-1","__idx":14},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["SAML SSO configured and working (Steps 1–4 above) - the SCIM section only appears once SSO is set up"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Owner"]}," role in Capsule"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["An Okta admin who can edit the app's provisioning settings"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"step-1-enable-scim-in-capsule","__idx":15},"children":["Step 1: Enable SCIM in Capsule"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Single Sign On"]},". Below your SSO connection you'll find the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SCIM provisioning"]}," section."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the identity provider dropdown, confirm ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta Workforce"]}," is selected. Capsule pre-selects it when your Sign In Endpoint is an Okta URL."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The provider selection controls how Capsule matches SCIM-provisioned users to SAML logins. Okta sends the login email in the SCIM ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["userName"]}," attribute, so Capsule keys the email off ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["userName"]},". With the wrong provider selected, provisioned users can't be matched at login."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enable SCIM"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SCIM endpoint URL"]}," that appears - you'll paste it into Okta in Step 3."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"step-2-generate-a-provisioning-token","__idx":16},"children":["Step 2: Generate a Provisioning Token"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Provisioning tokens"]},", click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Generate token"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Copy the token from the dialog ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["immediately - it is shown only once"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can keep multiple tokens active (useful for rotation), see when each was created and last used, and revoke any token at any time."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"step-3-enable-scim-provisioning-in-okta","__idx":17},"children":["Step 3: Enable SCIM Provisioning in Okta"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the Okta Admin Console, open the Capsule app → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["General"]}," tab → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["App Settings"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]},". Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Provisioning"]},", select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SCIM"]},", then ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},". A ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Provisioning"]}," tab appears on the app."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Provisioning"]}," tab → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Integration"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]},", fill in:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SCIM connector base URL"]}," - the Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SCIM endpoint URL"]}," from Step 1"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Unique identifier field for users"]}," - ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["userName"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Supported provisioning actions"]}," - check ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Push New Users"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Push Profile Updates"]},"; also check ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Push Groups"]}," if you plan to use group-to-role mappings (Step 4)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authentication Mode"]}," - ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["HTTP Header"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization"]}," - paste the provisioning token from Step 2"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Test Connector Configuration"]}," to verify, then ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Still on the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Provisioning"]}," tab, open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["To App"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]}," and enable ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create Users"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Update User Attributes"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Deactivate Users"]},", then ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Under the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["To App"]}," attribute mappings, delete the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Primary email type"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Primary phone type"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Address type"]}," mappings - Okta sends values for these that the Capsule endpoint rejects."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Users and groups already assigned on the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assignments"]}," tab are provisioned automatically; new assignments provision as you add them."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"step-4-map-okta-groups-to-capsule-roles-optional","__idx":18},"children":["Step 4: Map Okta Groups to Capsule Roles (Optional)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once groups are pushed from Okta (app → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Push Groups"]}," tab), you can drive Capsule roles from group membership:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Capsule, go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Single Sign On"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Group mappings"]}," and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add mapping"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Pick an Okta group and the Capsule role its members should receive - ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Admin"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Security Admin"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Viewer"]},", or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Legal Discovery"]},". If the group list is empty, push the groups in Okta first, then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Refresh groups"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["How group mappings behave:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Roles are applied at ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["every SSO sign-in"]},", so membership changes in Okta take effect the next time the user logs in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["While any mappings exist, group membership ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["replaces manual role assignment"]}," - a user's role follows their groups."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A user in multiple mapped groups gets the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["highest-privilege"]}," role among them."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A user in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["no"]}," mapped group has their role removed at next sign-in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Removing all mappings returns the tenant to manual role management."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"disabling-scim","__idx":19},"children":["Disabling SCIM"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Disable SCIM"]}," to stop provisioning: the endpoint stops accepting requests and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["all provisioning tokens are revoked"]},". Users that were already provisioned keep their access - manage or remove them from ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Users"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"scim-troubleshooting","__idx":20},"children":["SCIM Troubleshooting"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta's \"Test Connector Configuration\" fails"]}," - confirm the base URL matches the Capsule SCIM endpoint URL exactly, the Authentication Mode is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["HTTP Header"]},", and the token hasn't been revoked in Capsule. Generate a fresh token if in doubt."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Provisioned user can't sign in, or a duplicate account appears"]}," - the provider selection was likely wrong when SCIM was enabled. Disable SCIM, re-enable it with ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta Workforce"]}," selected, and confirm Okta's ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Unique identifier field for users"]}," is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["userName"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No groups appear in the Capsule group-mapping picker"]}," - groups only appear after Okta pushes them. Enable ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Push Groups"]}," on the app, push your groups, then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Refresh groups"]}," in Capsule."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"troubleshooting","__idx":21},"children":["Troubleshooting"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"redirected-to-okta-but-login-fails-with-a-saml-error","__idx":22},"children":["Redirected to Okta, but login fails with a SAML error"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cause"]},": The SP values in Okta don't match what Capsule generated, or the assertion isn't addressed correctly."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Solution"]},":"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Okta → app → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["General"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML Settings"]},", confirm the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single sign-on URL"]}," matches the Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Reply URL (ACS URL)"]}," and the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Audience URI"]}," matches the Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identifier (Entity ID)"]}," exactly (no trailing spaces) - see Step 3."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name ID format"]}," is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["EmailAddress"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application username"]}," is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Email"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Re-test after saving."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"login-succeeds-in-okta-but-capsule-rejects-the-assertion","__idx":23},"children":["Login succeeds in Okta but Capsule rejects the assertion"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cause"]},": Capsule can't verify the SAML signature - usually because Okta rotated its certificate and Capsule has a stale copy."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Solution"]},":"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Okta → app → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sign On"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["View SAML setup instructions"]},", download the current ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["X.509 Certificate"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Capsule, go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Single Sign On"]},", re-upload the certificate under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SSL/TLS Certificate"]},", and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"email-entered-on-the-capsule-login-page-doesnt-redirect-to-okta","__idx":24},"children":["\"Email\" entered on the Capsule login page doesn't redirect to Okta"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cause"]},": The email domain isn't in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorized Domains"]}," for the connection."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Solution"]},":"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm the address uses one of your configured domains (e.g., ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["name@your-company.com"]},")."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Capsule → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings → Single Sign On"]},", add the domain to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorized Domains"]}," (comma-separated) and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"user-reaches-capsule-but-their-name-is-blank","__idx":25},"children":["User reaches Capsule but their name is blank"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cause"]},": The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["given_name"]}," / ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["family_name"]}," attribute statements aren't being sent."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Solution"]},":"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Okta → app → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["General"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML Settings"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Attribute Statements"]},", confirm ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["given_name"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["family_name"]}," are present with values ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["user.firstName"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["user.lastName"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Have the user sign out and back in to refresh their profile."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"user-cant-sign-in-at-all","__idx":26},"children":["User can't sign in at all"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cause"]},": The user (or their group) isn't assigned the app in Okta."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Solution"]},":"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Okta → app → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assignments"]},", confirm the user or one of their groups is assigned."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Re-test SSO for that user."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"security--privacy","__idx":27},"children":["Security & Privacy"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No passwords reach Capsule"]}," - authentication happens entirely in Okta; Capsule only receives a signed SAML assertion."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Your policies stay in force"]}," - MFA, device trust, session lifetime, and conditional access are enforced by Okta at sign-in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Signed assertions"]}," - Capsule validates Okta's SAML signature against your uploaded certificate and rejects anything it can't verify."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Owner-only configuration"]}," - only Capsule ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Owners"]}," can view or change the SSO connection."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Access is governed in Okta"]}," - unassigning a user or group from the Okta app immediately removes their ability to sign in via SSO."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Email is the identity key"]}," - Capsule keys accounts on the Name ID (email), so keep it stable to avoid duplicate accounts."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"support","__idx":28},"children":["Support"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Need help with SSO?"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Documentation"]},": ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://docs.capsule.security"},"children":["docs.capsule.security"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Email Support"]},": support@capsule.security"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When contacting support, please include:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Your Okta org domain (e.g., ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["your-org.okta.com"]},")"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The email domain(s) users sign in with"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Your Okta IdP Single Sign-On URL"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Screenshots of any SAML error pages (the error usually appears after the redirect back from Okta)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Timestamp when the issue occurred"]}]}]},"headings":[{"value":"Okta SSO (SAML)","id":"okta-sso-saml","depth":1},{"value":"Overview","id":"overview","depth":2},{"value":"How It Works","id":"how-it-works","depth":2},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"Setup Overview","id":"setup-overview","depth":2},{"value":"Step 1: Create a SAML App Integration in Okta","id":"step-1-create-a-saml-app-integration-in-okta","depth":2},{"value":"Step 2: Configure the Connection in Capsule","id":"step-2-configure-the-connection-in-capsule","depth":2},{"value":"Step 3: Copy Capsule's SP Values Back into Okta","id":"step-3-copy-capsules-sp-values-back-into-okta","depth":2},{"value":"Steps","id":"steps","depth":3},{"value":"Step 4: Assign Users and Test","id":"step-4-assign-users-and-test","depth":2},{"value":"Assign access in Okta","id":"assign-access-in-okta","depth":3},{"value":"Test the connection","id":"test-the-connection","depth":3},{"value":"Attribute Mapping","id":"attribute-mapping","depth":2},{"value":"SCIM Provisioning (Optional)","id":"scim-provisioning-optional","depth":2},{"value":"Prerequisites","id":"prerequisites-1","depth":3},{"value":"Step 1: Enable SCIM in Capsule","id":"step-1-enable-scim-in-capsule","depth":3},{"value":"Step 2: Generate a Provisioning Token","id":"step-2-generate-a-provisioning-token","depth":3},{"value":"Step 3: Enable SCIM Provisioning in Okta","id":"step-3-enable-scim-provisioning-in-okta","depth":3},{"value":"Step 4: Map Okta Groups to Capsule Roles (Optional)","id":"step-4-map-okta-groups-to-capsule-roles-optional","depth":3},{"value":"Disabling SCIM","id":"disabling-scim","depth":3},{"value":"SCIM Troubleshooting","id":"scim-troubleshooting","depth":3},{"value":"Troubleshooting","id":"troubleshooting","depth":2},{"value":"Redirected to Okta, but login fails with a SAML error","id":"redirected-to-okta-but-login-fails-with-a-saml-error","depth":3},{"value":"Login succeeds in Okta but Capsule rejects the assertion","id":"login-succeeds-in-okta-but-capsule-rejects-the-assertion","depth":3},{"value":"\"Email\" entered on the Capsule login page doesn't redirect to Okta","id":"email-entered-on-the-capsule-login-page-doesnt-redirect-to-okta","depth":3},{"value":"User reaches Capsule but their name is blank","id":"user-reaches-capsule-but-their-name-is-blank","depth":3},{"value":"User can't sign in at all","id":"user-cant-sign-in-at-all","depth":3},{"value":"Security & Privacy","id":"security--privacy","depth":2},{"value":"Support","id":"support","depth":2}],"frontmatter":{"seo":{"title":"Okta SSO (SAML)"}},"lastModified":"2026-07-14T10:00:48.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/okta-sso","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}