Skip to main content
Step-by-step directions for connecting Okta to Invoca as your SAML identity provider, alongside the general steps in SAML SSO Setup.
Before you begin: Complete this guide alongside SAML SSO Setup — you’ll go back and forth between Okta and Invoca’s SSO Settings a few times. You need administrator access to your Okta org and Network Super User access to Invoca.

Part 1: Configure the Okta tile

  1. In the Okta Admin Console, go to Applications, then click Applications.
  2. Click Create App Integration.
  3. Select SAML 2.0 as the sign-in method, then click Next.
  4. Provide the general information for the integration, then click Next.
  5. Provide the SAML settings information for your integration. Your configuration may differ from Invoca’s defaults, since the dropdown options are unique to your application. If you need to map additional parameters, such as phone numbers, you may need to create a custom attribute and add it to the app — the app must be fully created first. See How to Add and Map Custom Attributes in Okta for Configuring Required SSO/SAML Parameters for details.
  6. Click Next.
  7. Provide configuration information about your app integration to Okta, then select Finish.

Part 2: Enable SSO in Invoca

Follow the steps in SAML SSO Setup to enable SSO on the Invoca side. All fields must be filled out before you can retrieve the metadata. If you’re unsure how to locate your SHA-1 or SHA-256 fingerprint, check the certificate details in your Okta application or contact your Okta administrator.

Part 3: Configure the SSO settings in Okta

Once the tile is configured, Okta provides instructions for completing the SAML setup. Click View SAML setup instructions for the steps to enter Invoca’s SAML endpoint(s) and metadata.

Part 4: Test the Okta tile and optional cleanup

Testing best practices: Once the SSO settings in Invoca are complete and your Okta tile is set up with SAML, go to the Okta User Home page and test the tile. Consider creating a Group in Okta and/or Group Rules for testing before inviting all users to the new SAML Invoca app. Optional cleanup: When enabling SSO, be aware that a user may temporarily have two authentication types. If you make SSO/SAML mandatory for all users, we recommend removing the “Credentials” user to avoid locking out that account — but first, add any saved reports to the “Single Sign On” user, since reports don’t transfer automatically.
If you encounter a 403 errorA 403 error when logging in via SAML/SSO usually indicates either a required-attributes issue or an invalid signature on the SAML response. Contact your account team or support@invoca.com if you need help troubleshooting.

Where to go next

SAML SSO Setup

How to Add and Map Custom Attributes in Okta for Configuring Required SSO/SAML Parameters

SAML SSO: Appendix

Last modified on September 21, 2026