> For the complete documentation index, see [llms.txt](https://doc.thordata.com/doc/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.thordata.com/doc/free-tools/sso/using-thordata-to-set-up-okta-sso.md).

# Using Thordata to set up Okta SSO

**Requirements:**

* An Okta organization account with administrator privileges.
* A Thordata account with administrator privileges.

**Steps:**

1. **Steps:**&#x49;n your Okta Admin Dashboard, go to **Applications > Applications**.\
   (`https://[your_domain]-admin.okta.com/admin/apps/active`)
2. Click **Create App Integration**.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F7B3F40ae5DfR4aFp1wJ8%2F1.png?alt=media&amp;token=7d90a485-0e30-421e-a1b8-eff1a4ce72df" alt="" width="563"><figcaption></figcaption></figure></div>

3. Select **OIDC - OpenID Connect** as the Sign-in method.
4. Choose **Web Application** as the Application type, then click **Next**.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FgSe9K9B6Iychc86PdDN1%2F2.png?alt=media&amp;token=07637013-ecec-413d-9957-4ce159c36fab" alt="" width="563"><figcaption></figcaption></figure></div>

5. You will be redirected to a new Web App Integration page. Here, you can name your app integration (we recommend using "Thordata Control Panel").
6. Under **Grant type**, select **Implicit** and **Authorization Code** \[Optional].

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FjDdHjf8icEETM468f0lA%2F3.png?alt=media&amp;token=de518a6e-327c-46d8-95b2-856976c73b7c" alt="" width="563"><figcaption></figcaption></figure></div>

7. Go to the Thordata Control Panel.
8. Open the **OKTA Configuration** dialog.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FekDMlzDfTT1DQK0hJXDg%2F4.png?alt=media&amp;token=b73e87b9-a1d8-4a3f-beff-2c2e63e58bb4" alt="" width="531"><figcaption></figcaption></figure></div>

9. Copy the **Sign-in redirect URI**.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F74pCXD5gSBHxGZ4CkNVf%2F%E6%9B%BF%E6%8D%A21.png?alt=media&amp;token=e1b19d12-b943-4b19-8d72-cebb4c75e6b5" alt="" width="563"><figcaption></figcaption></figure></div>

10. Paste it into the corresponding field in the new app settings in Okta.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F8TVMRfvO9PZ1CZctJLkT%2F6.png?alt=media&amp;token=ade7d05f-1c3f-4f5e-8c02-d4a88c155cb8" alt="" width="563"><figcaption></figcaption></figure></div>

11. Repeat the same process for the **Sign-out URI**.
12. Under **Assignments**, select the desired access level.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F8ogLEKUPErqP1E0veAbP%2F7.png?alt=media&amp;token=bac60127-f606-4cf5-81ec-94be187c4450" alt="" width="563"><figcaption></figcaption></figure></div>

13. Click **Save**.
14. You should now be on the settings page for the new app integration.

    Copy your **Client ID**, **Client Secret**, and **Okta Domain** to the OKTA settings dialog in the Thordata Control Panel.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F60NfvYNOk3pKDqcFQQ0l%2F8.png?alt=media&amp;token=e8e63791-2523-45a6-a1e9-1aef101d936e" alt="" width="545"><figcaption></figcaption></figure></div>

**Okta Domain：**

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FlgjamaOOogdZPpvfAaui%2Fimage.png?alt=media&amp;token=5d5fc0c9-de67-459f-baf7-e57da1081c64" alt="" width="512"><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2Fo61Wk8FOYddzJV0DMfNd%2F%E6%9B%BF%E6%8D%A22.png?alt=media&amp;token=38a018ee-6fef-4338-93aa-f9aeb60f3504" alt="" width="563"><figcaption></figcaption></figure></div>

15. You should go to Security-API-Tokens to create your token

<div><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F0ypT5h4RxUbvTDXjOJS9%2F14.png?alt=media&amp;token=52f694d3-3116-489b-8694-35ee544d314e" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FHZ5sCF4vQBb9JBckb9Js%2F15.png?alt=media&amp;token=c54a8177-3ade-4e70-b1bf-c835b64a7979" alt="" width="563"><figcaption></figcaption></figure></div>

<div><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F5UKnGYArqleOBHZVbnnQ%2F16.png?alt=media&amp;token=8f4f8d7e-5b1d-4079-82b4-906165f87c80" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F9mt7EthUBbFKGHHSGCkr%2F17.png?alt=media&amp;token=be4abcb5-6ef5-4fbf-b683-b36b85dbce0e" alt="" width="563"><figcaption></figcaption></figure></div>

Then copy it into the OKTA settings dialog in the Thourdata control panel.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FqBQA7xkg2qiCd0af7yLn%2F%E6%9B%BF%E6%8D%A23.png?alt=media&amp;token=64ee8574-7caf-47d5-8f6f-efd304c0700a" alt="" width="563"><figcaption></figcaption></figure></div>

16. Click "Activate". If you select "Allow everyone access", skip step 17.
17. Click **Activate**. *(If you selected "Allow everyone access," skip step 16.)*
18. Go to the **Assignments** tab and assign the users permitted to use this integration.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FIo8QcNRWpS27u08WKJT1%2F10.png?alt=media&amp;token=2bab1fc6-9ee6-469a-af89-7aae8ea91aba" alt="" width="563"><figcaption></figcaption></figure></div>

17. Go to the Thordata settings page and ensure all required users are displayed. *Note: We are currently working on providing user support – you should manage this manually for now.*

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FSFQUAu4nxpo6mb8yIiyr%2F11.png?alt=media&amp;token=495d149e-fd0e-42a9-83c2-d439e985f0d6" alt="" width="563"><figcaption></figcaption></figure></div>

The following steps are optional. They enable your users to initiate authentication from their dashboard or the Okta Chrome extension.

18. Scroll down to **General Settings** and click **Edit**.
19. &#x20;Configure the following settings:\
    \* **Login initiated by:** Okta or App\
    \* **App visibility:** Display application icon to users\
    \* **Login flow:** Redirect to app to initiate login (OIDC compliant)

Copy the **Initiate login URI** from the Control Panel.

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2FAE23d4tcq0T74CfdRjWz%2F%E6%9B%BF%E6%8D%A24.png?alt=media&amp;token=8bd53be5-ade3-44d3-9fa9-6bd61e30313c" alt="" width="563"><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://340306199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1wQhlaRQzrtcn9wgMUU5%2Fuploads%2F82w6HCYpxvzY3DiF6fwP%2F13.png?alt=media&amp;token=934eee69-7e43-40ce-a384-c59aa61077e9" alt="" width="563"><figcaption></figcaption></figure></div>

20. Save the changes. The integration is now ready.

**Important Notes:**

* The **Okta Domain** should be the one that appears in your app integration settings (e.g., `yourcompany.okta.com`), not the one you see as an administrator (e.g., `yourcompany-admin.okta.com`).
* Ensure the **credentials provided to Thordata are correct**, as we cannot verify them personally.
* The **Sign-in redirect URI is mandatory** for the SSO functionality to work.
* The **Initiate login URI is required** if you want to use the feature from the Okta Chrome extension or the Okta dashboard.
