Allocadia integrates with Okta via SAML 2.0. Here's the setup overview and what each side needs to configure.
Prerequisites
- Your Okta tenant with admin access.
- An Allocadia tenant on a version that supports SAML 2.0.
- An Allocadia admin to coordinate the SP-side configuration.
- An HTTPS endpoint on both sides.
Setup overview
The high-level flow:
- Create a SAML 2.0 application in Okta for Allocadia. The Okta app gallery may have an Allocadia template; if not, create a generic SAML 2.0 app.
- Configure the Okta app with Allocadia's Service Provider (SP) details — ACS URL, Entity ID, logout URL. Contact Support for your tenant's specific values.
- Set up attribute statements in the Okta app — NameID, email, and any group assertions Allocadia needs for your account.
- Export Okta's metadata (Entity ID, SSO URL, signing certificate) and provide to Allocadia Support.
- Allocadia Support configures the SP side to trust Okta as the IdP.
- Assign users or groups to the Okta app.
- Test with a pilot user before broad rollout.
Allocadia Support typically coordinates the setup — reach out to kick it off.
Attribute statements
The specific attribute set your account needs depends on configuration, but typically:
- NameID — the user identifier (usually email).
- Email — matches against Allocadia user records.
- Groups — optional, for group-based provisioning.
Attribute names and values are case-sensitive.
Group-based provisioning (optional)
If you use Okta groups to control who gets Allocadia access, map group names between the two systems so Okta-side group changes propagate automatically. This is configured per account.
Common pitfalls
- Email format mismatch between Okta and Allocadia user records.
- Certificate rotation on the Okta side — see SSO login to Allocadia fails after our IdP certificate was rotated.
- Missing or misspelled attribute names.
Maintenance
- Notify Allocadia Support a week before scheduled Okta certificate rotations — we can stage the new cert in advance.
- Review the Okta app assignment list periodically to confirm access is up to date.
Comments
Please sign in to leave a comment.