Skip to main content

Set up SAML SSO with Okta

General steps to configure Okta for Cye platform SSO integration.

Updated over 2 weeks ago

Overview

This article provides general guidelines for integrating Okta with Cye using SAML-based Single Sign-On (SSO). These steps help you prepare and connect the two systems securely.

This setup must be completed by an administrator in both Cye platform and Okta. It assumes you’ve already enabled SSO in Cye platform.


Steps

  1. Create a new app in Okta

    • In your Okta dashboard, go to Applications and create a new app integration:

    • Select SAML 2.0 as the sign-on method.

    • Add a name for the app (e.g., “Cye”) and click Next:

  2. Enter SAML settings from Cye

    • In the Single sign-on URL and Entity ID fields, paste the values from the Cye platform Company Profile > SSO section.

    • Note: Cye acts as the Service Provider (SP) in this configuration.

  3. Set attribute statements

    • Complete the attribute statements required by your organization.

    • This step is required — missing attributes may prevent user login:

  4. Add users and groups

    • Assign the appropriate users and groups to the app in Okta.

    • Important: Ensure that usernames or IDs used in Okta exactly match those used in Cye platform— including letter casing.

  5. Get metadata and entity ID

    • Copy the Metadata URL from Okta and paste it into the IdP Metadata URL field in Cye platform:

    • To find the IdP Entity ID, click More details under the Metadata URL section in Okta:

    • Copy the value in the Issuer field and paste it into Cye platform’s IdP Entity ID field:


Important notes

  • This article provides general guidance — refer to your internal security team for exact attribute requirements.

  • All user identifiers must match between Okta and Cye platform — mismatched casing or naming will prevent login.


Wrap-up / Next Steps

Once you've completed the Okta side, return to Cye platform to finalize the SSO setup. If anything doesn’t match exactly, users may be blocked from logging in — so double-check the details before saving.

Did this answer your question?