# Set up SSO with Okta

> Connect Okta to Privatus Analytics with SAML 2.0 or OpenID Connect single sign-on. Create the app integration, copy the values, assign people and test.

1. In the Okta Admin Console go to **Applications → Applications → Create
   App Integration**, choose **SAML 2.0**, and name it "Privatus Analytics".
2. **SAML settings:**

   | Okta field | Value |
   |---|---|
   | Single sign-on URL | `https://privatusanalytics.com/users/auth/saml/callback` (keep "Use this for Recipient URL and Destination URL" checked) |
   | Audience URI (SP Entity ID) | `https://privatusanalytics.com/users/auth/saml/metadata?workspace=ws_…` |
   | Name ID format | EmailAddress |
   | Application username | Email |

   Optionally add an attribute statement `name` → `user.displayName`.
3. Finish, then open **Sign On → SAML 2.0 → More details** and copy the
   **Sign on URL**, **Issuer** and **Signing certificate**.
4. In Privatus Analytics, **Workspace settings → SSO → SAML**: paste the
   three values, list your email domains, and save.
5. In Okta, **Assignments**: assign the people or groups who should have
   access.
6. **Test** in Privatus Analytics, then **Activate**.

For automatic provisioning, enable SCIM in the same Okta app: see
[SCIM](/docs/teams/scim).

Prefer OpenID Connect? Create an **OIDC - Web Application** instead, with
the sign-in redirect URI `https://privatusanalytics.com/users/auth/openid_connect/callback`,
and paste the issuer (`https://<your-okta-domain>`), client id and secret
into the OIDC form.
