> ## Documentation Index
> Fetch the complete documentation index at: https://docs.isotopes.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SSO quick setup

> The fast, assisted path to sign in to Isotopes AI with Okta — we pre-generate the values you need, you spend about 20 minutes in Okta. Estimated setup time: 20 minutes.

Setup instructions to sign in to Isotopes AI with an Okta account. Estimated setup time: 20 minutes.

## What we have already done

Your account is ready, and we have generated the two values Okta needs from us:

| Value | Where it goes in Okta |
| - | - |
| Entity ID | Audience URI |
| ACS (Reply) URL | Single sign-on URL |

Both values should be available in the onboarding email (they are to be used exactly as sent).

> **Note:** They might look similar. The Entity ID is the short one ending in `/saml`. The ACS URL is longer.

## Step 1: Create the app in Okta

1. In your Okta admin console, go to **Applications → Applications → Create App Integration**.
2. Select **SAML 2.0** and click **Next**.
3. Give the name **Isotopes AI** and click **Next**.
4. On the **Configure SAML** screen, fill in the following fields:

| Field | Value |
| - | - |
| Single sign-on URL | ACS (Reply) URL from email. Use this for **Recipient URL** and **Destination URL** — leave checked. |
| Audience URI (SP Entity ID) | Entity ID from email |
| Name ID format | `EmailAddress` |
| Application username | `Email` |

## Step 2: Add the attributes

On the same screen, scroll down to **Attribute Statements** and add these two rows:

| Name | Name format | Value |
| - | - | - |
| `email` | Unspecified | `user.email` |
| `name` | Unspecified | `user.displayName` |

Right under there is **Group Attribute Statements**. Add one row:

| Name | Name format | Filter |
| - | - | - |
| `groups` | Unspecified | Matches regex `.*` |

That last row tells us which Okta groups someone belongs to. We use it to set their access level. If you would rather not send every group, use **Starts with** and a prefix that covers the ones you want us to see.

Then click **Next**, choose **I'm an Okta customer adding an internal app**, and click **Finish**.

## Step 3: Send the following items to Isotopes

On the **Sign On** tab that was just created, click **View SAML setup instructions**. The following items are available on that page:

1. Identity Provider Issuer
2. Identity Provider Single Sign-On URL
3. X.509 Certificate — copy the whole block, including the `BEGIN` and `END` lines.

The next item is your group list. Tell us which Okta groups should get which access level, and what everyone else should get by default:

| Access level | What it allows |
| - | - |
| Admin | Everything, including settings and managing people |
| Editor | Create and edit |
| Viewer | View only |

Example: "our `okta-admins` group should be Admin, everyone else Viewer" is enough.

## What happens next

We run a connection test on our end. Following that, we will be able to onboard new users.
