Okta
This guide sets up SAML single sign-on from Okta, then optional SCIM
provisioning. You’ll need an Okta administrator who can create app
integrations and a Twelfth workspace owner or admin. Read
Single sign-on & SCIM first if you haven’t.
1. Create the app integration
- In the Okta Admin Console, open Applications → Applications → Create App
Integration. - Choose SAML 2.0 and continue. Name it Twelfth.
2. Paste Twelfth’s details into Okta
In Twelfth, open Settings → Workspace → Security & SSO → Single sign-on; under Create the
app in your identity provider the values below have copy buttons. On Okta’s
Configure SAML page, set:
| Okta field | Twelfth value |
|---|---|
| Single sign-on URL | Reply URL (Assertion Consumer Service) from the panel |
| Audience URI (SP Entity ID) | Identifier (Entity ID) from the panel |
| Name ID format | EmailAddress |
| Application username |
Under Attribute Statements, add:
| Name | Value |
|---|---|
email |
user.email |
firstName |
user.firstName |
lastName |
user.lastName |
Finish (choose I’m an Okta customer adding an internal app if asked).
3. Paste Okta’s details into Twelfth
- On the app’s Sign On tab, under SAML 2.0, copy the Metadata URL.
- In Twelfth’s panel, choose SAML 2.0, enter your email domain, paste
the metadata URL, and press Register identity provider.
4. Prove you own the domain
Add the DNS TXT record the panel shows, then press Check now.
5. Assign people and test
Assign yourself on the app’s Assignments tab, sign out of Twelfth, and use
See other login methods → Continue with single sign-on on the
login page.
6. Provisioning (SCIM)
- In Twelfth’s panel, press Generate SCIM token and copy the token (shown
once) and the Tenant URL. - In Okta, on the app’s General tab, edit App Settings and tick Enable
SCIM provisioning. A Provisioning tab appears. - Under Provisioning → Integration, set the SCIM connector base URL to
the Tenant URL, Unique identifier field for users toemail, tick
Push New Users, Push Profile Updates and Push Groups, choose
HTTP Header authentication and paste the token. Test Connector
Configuration, then save. - Under Provisioning → To App, enable Create Users, Update User
Attributes and Deactivate Users.
People assigned join the workspace; people unassigned or deactivated are
deactivated in Twelfth (never deleted). Roles and remits are still set in
Twelfth.