Okta

This guide sets up SAML single sign-on from Okta, then optional SCIM
provisioning
. You’ll need an Okta administrator who can create app
integrations and a Twelfth workspace owner or admin. Read
Single sign-on & SCIM first if you haven’t.

1. Create the app integration

  1. In the Okta Admin Console, open Applications → Applications → Create App
    Integration
    .
  2. Choose SAML 2.0 and continue. Name it Twelfth.

2. Paste Twelfth’s details into Okta

In Twelfth, open Settings → Workspace → Security & SSO → Single sign-on; under Create the
app in your identity provider
the values below have copy buttons. On Okta’s
Configure SAML page, set:

Okta field Twelfth value
Single sign-on URL Reply URL (Assertion Consumer Service) from the panel
Audience URI (SP Entity ID) Identifier (Entity ID) from the panel
Name ID format EmailAddress
Application username Email

Under Attribute Statements, add:

Name Value
email user.email
firstName user.firstName
lastName user.lastName

Finish (choose I’m an Okta customer adding an internal app if asked).

3. Paste Okta’s details into Twelfth

  1. On the app’s Sign On tab, under SAML 2.0, copy the Metadata URL.
  2. In Twelfth’s panel, choose SAML 2.0, enter your email domain, paste
    the metadata URL, and press Register identity provider.

4. Prove you own the domain

Add the DNS TXT record the panel shows, then press Check now.

5. Assign people and test

Assign yourself on the app’s Assignments tab, sign out of Twelfth, and use
See other login methods → Continue with single sign-on on the
login page.

6. Provisioning (SCIM)

  1. In Twelfth’s panel, press Generate SCIM token and copy the token (shown
    once) and the Tenant URL.
  2. In Okta, on the app’s General tab, edit App Settings and tick Enable
    SCIM provisioning
    . A Provisioning tab appears.
  3. Under Provisioning → Integration, set the SCIM connector base URL to
    the Tenant URL, Unique identifier field for users to email, tick
    Push New Users, Push Profile Updates and Push Groups, choose
    HTTP Header authentication and paste the token. Test Connector
    Configuration
    , then save.
  4. Under Provisioning → To App, enable Create Users, Update User
    Attributes
    and Deactivate Users.

People assigned join the workspace; people unassigned or deactivated are
deactivated in Twelfth (never deleted). Roles and remits are still set in
Twelfth.