Security Assertion Markup Language (SAML) is a standard for logging users into applications based on their sessions in another context. This single sign-on (SSO) login standard has significant advantages over logging in using a username/password:
Provide the name and logo of the application and proceed by clicking on “Next” button
Uncheck the “Use this for Recipient URL and Destination URL” checkbox under the Single Sign on URL field
Copy the Assertion Consumer Service URL from shufti back office settings and paste it into the Single sign-on URL field (Check Steps 1-5)
Copy Sign on URL from shufti back office settings and paste it into the Recipient URL and Destination URL field (Check Steps 1-5)
Copy Identifier (Entity ID) from shufti back office settings and paste it into the Audience URI (SP Entity ID) field (Check Steps 1-5)
Change Name ID format to EmailAdress and Application username to Email from dropdowns
Proceed by clicking the “Next” button, ensuring that all other settings remain unchanged.
Select the option “I’m an Okta customer adding an internal app” and click on finish
Select “Sign on“ tab.
Scroll down and click on View SAML setup instructions
Copy Identity Provider Single Sign-On URL from okta and paste it into shufti back office SSO URL field (Check Steps 1-5)
Copy Identity Provider Issuer from okta and paste it into Shufti pro’s back office Identity Provider URL field (Check Steps 1-5)
Copy x.509 Certificate (without BEGIN CERTIFICATE and END CERTIFICATE comments) from okta and paste it into Shufti pro’s back office Public Certificate field (Check Steps 1-5)
Now enable SSO from Shufti’s Back Office by clicking on Toggle button on SAML Authentication section (Check Steps 1-5)
Now click on submit button
To allow users to login using credentials even when SSO is enabled then uncheck this “Do you want to restrict secondary users from login with their credentials if SSO in enabled?” option and click on submit button
IdP-initiated authentication flow
User will login into their okta account
From My App click on the shufti app
SP-initiated authentication flow
Open Back Office and click on Log in with single sign-on (SSO) instead
Enter your email
If SSO is enabled for you, it will take you to your IdP.
If you are already logged in there it will automatically redirect to the shufti otherwise ask you to enter your credentials and then redirect you to the shufti.
Add User in Okta
Click on People from okta admin dashboard
Click on Add Person
Fill in the user details and click on save Ps. Email is required
Refresh the page and the user will be added
Assign Application to User
Click on Application from okta admin dashboard
Select the application in which you want to add user
Click on the Assignments tab
Click on Assign to People
Click on Assign
Verify user email and click on save and Go Back
We use cookies to improve user experience, personalise content delivery, and improve website navigation and performance. By continuing use of our website, you consent to our use of cookies. Read how we use cookies from our Cookie Policy.
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Marketing/ target cookies are usually used to show you advertisements that meet your interest. When you visit another website, your browser’s cookie is recognized and selected ads are displayed to you based on the information stored in this cookie (art. 6 par. 1 p.1a GDPR)