Okta
8 min
overview okta https //www okta com/ is a cloud based identity and access management (iam) platform that enables secure, single sign on (sso) access to applications and services using one set of credentials integration guide the goal of this is to provide a comprehensive guide allowing for a successful setup and integration of okta as an identity provider to shi one if using okta as an idp is a requirement for your company to onboard with shi one, please familiarize yourself with this documentation and confirm the requirements and permissions necessary and then reach out to your account executive or shi representative to start the process prerequisites required access & permissions administrative access to their okta tenant ability to create new applications in okta ability to configure application settings and assignments to setup the okta integration login to the okta console as an admin user enter the admin console of okta open the applications menu and click create app integration for the sign in method select oidc for the application type, select web application once in the new application setup, most of the default settings will remain the following will need to be changed fill out the app integration name we recommend "shi one" especially if your company wants to leverage the application dashboard built into okta for your users enter https //login shi com/login/callback into the sign in redirect uris field the sign out redirect uris field can be blank if you need to remove a default, click on the x under assignments , select your desired option you will have to determine this setting based on your okta setup and who needs access to shi one it can allow everyone in your okta idp access or certain groups of users which you will have to setup and is outside the scope of this document once, you're finished, click save once the application is saved, click edit in general settings scroll down to the login section update the login initiated by option to either okta or app update the initiate login uri to https //one shi com/api/idpauthentication/idp initiate?connection=companyname sso note you will need to provide what you put into the end of this url to shi there can be no underscores, just your company name with " sso" appended to it for example, "acmeco sso" after saving, the settings should look like the screenshot below (with "acmeco" replaced with your company name or identifier) lastly, save your changes requesting from shi we have a secure mailbox setup for the items you will need to provide to complete the integration please send an encrypted email with a txt file attached containing the four items below if you need help sending an encrypted email or have any questions, feel free to contact the same email address email shione sso onboarding\@shi com the information that you will need to provide shi to complete the integration are the company name or identifier you entered for the initiate login uri above providing the whole uri is preferred for validation the client id of the application the secret of the application the okta domain from the admin console (see screenshot below) it will be in the mydomain okta com format post submission information that should be all that is needed to complete the integration once this information is provided to shi, we will complete the integration on our side and ask users to test at the current time shi only supports idp initiated login so if your organization is leveraging the okta apps dashboard, be sure to add this app to it for your users if not, users will need to use the initiate login uri it may be preferable for your organization to map an internal dns entry to the initiate login uri but that is optional we recommend having users log in via the okta apps dashboard or having them bookmark the initiate login uri