What we have already done
Your account is ready, and we have generated the two values Okta needs from us:
Both values should be available in the onboarding email (they are to be used exactly as sent).
Note: They might look similar. The Entity ID is the short one ending in /saml. The ACS URL is longer.
Step 1: Create the app in Okta
- In your Okta admin console, go to Applications → Applications → Create App Integration.
- Select SAML 2.0 and click Next.
- Give the name Isotopes AI and click Next.
- On the Configure SAML screen, fill in the following fields:
Step 2: Add the attributes
On the same screen, scroll down to Attribute Statements and add these two rows:
Right under there is Group Attribute Statements. Add one row:
That last row tells us which Okta groups someone belongs to. We use it to set their access level. If you would rather not send every group, use Starts with and a prefix that covers the ones you want us to see.
Then click Next, choose I’m an Okta customer adding an internal app, and click Finish.
Step 3: Send the following items to Isotopes
On the Sign On tab that was just created, click View SAML setup instructions. The following items are available on that page:- Identity Provider Issuer
- Identity Provider Single Sign-On URL
- X.509 Certificate — copy the whole block, including the
BEGINandENDlines.
Example: “our
okta-admins group should be Admin, everyone else Viewer” is enough.