Skip to main content

How do I set up SSO with Okta?

Learn how to connect Okta to Marvia with Single Sign-On (SSO).

Written by Maarten Peters

This guide is for Okta administrators. Replace {your-portal-domain} with your Marvia portal host, for example acme.getmarvia.com. Marvia connects to Okta with SAML 2.0. OpenID Connect is not used for this integration.


Create a SAML 2.0 app in Okta, then send Marvia the values listed at the end of this page. After we save them, users can sign in with the SSO button on your Marvia login page.
​

1. Create the SAML app

  1. In Okta, go to Applications → Applications → Create App Integration.

  2. Choose SAML 2.0.

  3. Give the app a name, for example Marvia.

2. Configure SAML settings

Use these values in the SAML settings:

Okta field

Value

Single sign-on URL

https://{your-portal-domain}/saml/acs

Use this for Recipient URL and Destination URL

Enabled

Audience URI (SP Entity ID)

https://{your-portal-domain}/saml/metadata

Name ID format

EmailAddress

Application username

Email

You can also import Marvia’s metadata from:

https://{your-portal-domain}/saml/metadata
​

3. Attribute statements

Add these attributes. Use name format Unspecified.

Name

Value

firstName

user.firstName

lastName

user.lastName

email

user.email

Groups (optional)

If users should be placed in Marvia groups, add a Group Attribute Statement:

Name

Filter

groups

Matches regex .*, or only the groups that should sync

Locations (optional)

If you use location or branch access in Marvia, add:

Name

Value

Name

Value

locations

The Okta profile attribute that holds the location name

4. Assign users

In Okta, assign the users or groups that should be able to sign in to Marvia.
​

5. Send these values to Marvia

From the app’s Sign On tab, open View SAML setup instructions and send us:

  • Identity Provider Issuer (Entity ID)

  • Identity Provider Single Sign-On URL

  • X.509 Certificate, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines

  • Single Logout URL, if you use it (optional)

Once we have saved these on our side, users can sign in with the SSO button on your Marvia login page.

Did this answer your question?