Skip to main content

Okta SSO Configuration Guide

How to set up Okta Single Sign-On integration for ClearVector

Supported features

  • Service Provider (SP)-Initiated SSO (Single Sign-On) - this authentication flow occurs when a user attempts to sign in to the ClearVector platform from its public application URL.

  • Identity Provider (IdP)-Initiated SSO (Single Sign-on) - this authentication flow occurs when a user attempts to sign in to the ClearVector platform from the Okta dashboard or with a custom link.

  • Invite-only provisioning - Users must be invited to ClearVector from within a ClearVector workspace before they can sign in with Okta SSO.

  • Just-In-Time provisioning - Users can sign in to ClearVector without an invitation after they are assigned to the ClearVector app in Okta.

For more information on the listed features, visit the Okta Glossary. You can find the ClearVector OIN integration at https://www.okta.com/integrations/clearvector.

Prerequisites

Before you can enable single sign-on to ClearVector with Okta, you must:

  • Sign up for a ClearVector account and create a workspace

  • Request the IdP manager role for your ClearVector user account

  • Enable the Identity provider feature for your ClearVector customer account

  • Enable the Identity provider feature in at least one ClearVector workspace where you will manage the identity provider configuration

  • Have admin access to an Okta account

  • If you have deployed a Private SaaS instance of ClearVector in your own AWS account, you will need to have your custom domain and auth domain values ready

Configuration

In Okta

  • Go to Applications -> Browse App Catalog and search for the ClearVector application.

  • Install the application and enter your customer ID. You can find your customer ID in ClearVector on the Settings -> Profile page.

  • Enter your custom domain and auth domain if you are configuring Okta for Private SaaS.

  • Assign users or groups that should be able to sign into ClearVector.

  • Go to the ClearVector app -> Sign On tab and note the Client ID and Client secret.

In ClearVector

  • Go to Settings -> Single sign-on and click "Add an identity provider".

  • Select the identity provider type for Okta.

  • Enter the the Client ID and Client secret from your Okta ClearVector app.

  • Enter your Okta domain. You can find your Okta domain in your Okta admin console in the upper right corner.

  • Save the identity provider configuration.

SP-initiated SSO

This sign-in process is initiated from the ClearVector platform URL. For commercial customers, this will be https://app.clearvector.com. For Private SaaS customers it will be your custom app domain.

  1. In your browser, navigate to the ClearVector platform URL.

  2. Enter your Okta username, click "Next" and then click your Okta integration provider name.

  3. You will be redirected to Okta to sign in.

IdP-initiated SSO

This sign-in process is initiated from your Okta dashboard or from a custom link.

  1. In your Okta dashboard, click the tile named "ClearVector".

  2. You should be redirected to ClearVector and signed in.

Just-In-Time provisioning

After you add an identity provider to ClearVector, you can optionally select Just-In-Time (JIT) user provisioning. This allows an SSO user to sign in to ClearVector without being invited by an existing user. SSO users provisioned with JIT are not automatically added to any workspace.

Require SSO

After you add an identity provider to ClearVector, you can optionally enable the Require SSO setting to prevent any users who do not have an SSO user account from signing in. Users who previously signed in to ClearVector with an email address and password will need to sign in with an SSO user account instead.

Caution

Some ClearVector features behave differently with SSO configured.

  • Workspace invitations - After you add an identity provider to ClearVector, any new users you invite to your workspaces will be SSO users. They will receive a workspace invitation email but they will not receive a ClearVector platform invitation email with a temporary password. If you would like to continue to invite users who do not sign in with SSO, contact ClearVector support.

  • SSO-linked users - After you add an identity provider to ClearVector and sign in with SSO, your SSO user account will be linked to your existing ClearVector user account. Your existing workspace membership and roles will be available to your SSO user account. If you do not enable the "Require SSO" setting, you will still be able to sign in with your ClearVector email and password if desired.

  • Lock out protection - You can add and remove identity providers as desired as long as you have at least one remaining method to sign in. If you have an existing ClearVector user account, you can remove all SSO identity providers. Be careful when removing identity providers if you have already invited other SSO users to ClearVector. They may not be able to sign in and you will have to re-invite them.

Did this answer your question?