> ## Documentation Index
> Fetch the complete documentation index at: https://docs.invoca.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure SSO with Okta

> Step-by-step directions for connecting Okta to Invoca as your SAML identity provider, alongside the general steps in [SAML SSO Setup](/s/article/jhdcp92865-570).

**Before you begin:** Complete this guide alongside [SAML SSO Setup](/s/article/jhdcp92865-570) — you'll go back and forth between Okta and Invoca's SSO Settings a few times. You need administrator access to your Okta org and Network Super User access to Invoca.

## Part 1: Configure the Okta tile

1. In the Okta Admin Console, go to **Applications**, then click **Applications**.
2. Click **Create App Integration**.
3. Select **SAML 2.0** as the sign-in method, then click **Next**.
4. Provide the general information for the integration, then click **Next**.
5. Provide the SAML settings information for your integration. Your configuration may differ from Invoca's defaults, since the dropdown options are unique to your application. If you need to map additional parameters, such as phone numbers, you may need to create a custom attribute and add it to the app — the app must be fully created first. See [How to Add and Map Custom Attributes in Okta for Configuring Required SSO/SAML Parameters](/s/article/How-to-Add-and-Map-Custom-Attributes-in-Okta-for-Configuring-Required-SSO-SAML-Parameters) for details.
6. Click **Next**.
7. Provide configuration information about your app integration to Okta, then select **Finish**.

## Part 2: Enable SSO in Invoca

Follow the steps in [SAML SSO Setup](/s/article/jhdcp92865-570) to enable SSO on the Invoca side. All fields must be filled out before you can retrieve the metadata.

If you're unsure how to locate your SHA-1 or SHA-256 fingerprint, check the certificate details in your Okta application or contact your Okta administrator.

## Part 3: Configure the SSO settings in Okta

Once the tile is configured, Okta provides instructions for completing the SAML setup. Click **View SAML setup instructions** for the steps to enter Invoca's SAML endpoint(s) and metadata.

## Part 4: Test the Okta tile and optional cleanup

**Testing best practices:** Once the SSO settings in Invoca are complete and your Okta tile is set up with SAML, go to the Okta User Home page and test the tile. Consider creating a Group in Okta and/or Group Rules for testing before inviting all users to the new SAML Invoca app.

**Optional cleanup:** When enabling SSO, be aware that a user may temporarily have two authentication types. If you make SSO/SAML mandatory for all users, we recommend removing the "Credentials" user to avoid locking out that account — but first, add any saved reports to the "Single Sign On" user, since reports don't transfer automatically.

<Note>
  **If you encounter a 403 error**

  A 403 error when logging in via SAML/SSO usually indicates either a required-attributes issue or an invalid signature on the SAML response. Contact your account team or [support@invoca.com](mailto:support@invoca.com) if you need help troubleshooting.
</Note>

## Where to go next

<CardGroup>
  <Card title="SAML SSO Setup" icon="key" href="/s/article/jhdcp92865-570" horizontal />

  <Card title="How to Add and Map Custom Attributes in Okta for Configuring Required SSO/SAML Parameters" icon="user-gear" href="/s/article/How-to-Add-and-Map-Custom-Attributes-in-Okta-for-Configuring-Required-SSO-SAML-Parameters" horizontal />

  <Card title="SAML SSO: Appendix" icon="code" href="/s/article/saml-sso-appendix" horizontal />
</CardGroup>
