SSO setup — Okta with Allocadia

Allocadia integrates with Okta via SAML 2.0. Here's the setup overview and what each side needs to configure.


Prerequisites

  • Your Okta tenant with admin access.
  • An Allocadia tenant on a version that supports SAML 2.0.
  • An Allocadia admin to coordinate the SP-side configuration.
  • An HTTPS endpoint on both sides.

Setup overview

The high-level flow:

  1. Create a SAML 2.0 application in Okta for Allocadia. The Okta app gallery may have an Allocadia template; if not, create a generic SAML 2.0 app.
  2. Configure the Okta app with Allocadia's Service Provider (SP) details — ACS URL, Entity ID, logout URL. Contact Support for your tenant's specific values.
  3. Set up attribute statements in the Okta app — NameID, email, and any group assertions Allocadia needs for your account.
  4. Export Okta's metadata (Entity ID, SSO URL, signing certificate) and provide to Allocadia Support.
  5. Allocadia Support configures the SP side to trust Okta as the IdP.
  6. Assign users or groups to the Okta app.
  7. Test with a pilot user before broad rollout.

Allocadia Support typically coordinates the setup — reach out to kick it off.

Attribute statements

The specific attribute set your account needs depends on configuration, but typically:

  • NameID — the user identifier (usually email).
  • Email — matches against Allocadia user records.
  • Groups — optional, for group-based provisioning.

Attribute names and values are case-sensitive.

Group-based provisioning (optional)

If you use Okta groups to control who gets Allocadia access, map group names between the two systems so Okta-side group changes propagate automatically. This is configured per account.

Common pitfalls

  • Email format mismatch between Okta and Allocadia user records.
  • Certificate rotation on the Okta side — see SSO login to Allocadia fails after our IdP certificate was rotated.
  • Missing or misspelled attribute names.

Maintenance

  • Notify Allocadia Support a week before scheduled Okta certificate rotations — we can stage the new cert in advance.
  • Review the Okta app assignment list periodically to confirm access is up to date.

Related articles

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.