Set up SSO with Okta
Connect Okta to Privatus Analytics with SAML 2.0 or OpenID Connect single sign-on. Create the app integration, copy the values, assign people and test.
- In the Okta Admin Console go to Applications → Applications → Create App Integration, choose SAML 2.0, and name it "Privatus Analytics".
- SAML settings:
| Okta field | Value |
|---|---|
| Single sign-on URL | https://privatusanalytics.com/users/auth/saml/callback (keep "Use this for Recipient URL and Destination URL" checked) |
| Audience URI (SP Entity ID) | https://privatusanalytics.com/users/auth/saml/metadata?workspace=ws_… |
| Name ID format | EmailAddress |
| Application username | Email |
Optionally add an attribute statement name → user.displayName.
- Finish, then open Sign On → SAML 2.0 → More details and copy the Sign on URL, Issuer and Signing certificate.
- In Privatus, Workspace settings → SSO → SAML: paste the three values, list your email domains, and save.
- In Okta, Assignments: assign the people or groups who should have access.
- Test in Privatus, then Activate.
For automatic provisioning, enable SCIM in the same Okta app: see SCIM.
Prefer OpenID Connect? Create an OIDC - Web Application instead, with
the sign-in redirect URI https://privatusanalytics.com/users/auth/openid_connect/callback,
and paste the issuer (https://<your-okta-domain>), client id and secret
into the OIDC form.