Prerequisites
- An Okta account with admin access
- A verified custom domain on your Auth application
Configure Okta SAML
1
Create a SAML app integration in Okta
- Log in to the Okta Admin Console
- Navigate to Applications > Applications
- Click Create App Integration
- Select SAML 2.0 as the sign-in method, then click Next
- Enter a name (e.g. “Prelude Auth”) and click Next
- On the Configure SAML screen, enter temporary placeholders for now. You will replace them in a later step:
- Single sign-on URL:
https://example.com/acs - Audience URI (SP Entity ID):
https://example.com
- Single sign-on URL:
- Set Name ID format to
EmailAddressand Application username toEmail - Click Next, then Finish
2
Copy Okta's metadata URL
On the application’s Sign On tab, find the Metadata URL (under SAML Signing Certificates / More details). It looks like:You will pass this URL to Prelude in the next step so the IdP Entity ID, SSO URL, and signing certificate are imported automatically.
3
Create the SAML connection in Prelude
Create the connection from Okta’s metadata. Start it disabled. You will enable it once the SP URLs are wired back into Okta.
The response contains an
sp block with the values you need next:4
Paste the SP URLs back into Okta
Return to the Okta application’s General tab and Edit the SAML settings:
- Set Single sign-on URL to the
sp.acs_urlfrom the response - Set Audience URI (SP Entity ID) to the
sp.entity_idfrom the response - Click Save
The values must match exactly, no trailing slash, and
https only.5
Assign users and enable the connection
- On the Okta Assignments tab, assign the people or groups who should have access.
- Enable the Prelude connection:
Rotating the IdP certificate
When Okta rotates its signing certificate, update the connection’s IdP block (the Entity ID is immutable, to change it, delete and recreate the connection):Delete the connection
saml:<connection_id> user identifiers are retained so historical sessions stay auditable.