---
title: Okta SAML
slug: okta-saml
description: Set up SAML SSO for Enterprise organizations.
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/e_qHb1m7hHbasnTc0QETS_1.png
docTags: 
createdAt: 2025-02-03T13:28:13.882Z
---

:::hint{type="info"}
This feature is available to Enterprise customers.
:::

The following manual configuration creates an SAML SSO configuration for your Enterprise organization.

## Prerequisites

- `Owner` role in an Enterprise organization
- Okta account with admin access

## Supported features

This configuration supports the following:

- Service Provider initiated SSO
- Single Log Out \[optional]

## Configuration steps

Before configuring SSO, you need to assign a namespace and create a Service Provider certificate and private key. These important steps provide information you need to enter later.

### Create your namespace

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **Namespace**, enter the namespace you want for your organization. For example, `acmecorp`. Your organization members enter this namespace when they log in via SSO.
:::

:::WorkflowBlockItem
Under **SSO type**, select **SAML 2.0**.
:::

:::WorkflowBlockItem
Copy the **Redirect URL** and save it in a safe place. You will use this later when you create your SAML integration in Okta.
:::
::::

### Download your Make Service Provider certificate

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Scroll down to find **Service Provider Certificates**.
:::

:::WorkflowBlockItem
Find your new certificate. Refer to the **Valid from** and **Expires** dates if you are unsure.
:::

:::WorkflowBlockItem
On the right side of the row for your certificate, click the icon.
:::

:::WorkflowBlockItem
Select **Download**.
:::
::::

Your browser downloads your SP certificate as a `.pem` file. You can find it in your downloads folder.

### Create an SAML integration

::::WorkflowBlock
:::WorkflowBlockItem
Log in to Okta and go to **Applications > Applications**.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-Z4pJ5QzVF8vN-HhMSCek4-20250210-120304.png" size="40" width="524" height="1254" position="flex-start" alt="Okta - Applications" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Create App Integration**.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-vjKb8zeRXvjjIOTDQWezs-20250210-120518.png" size="80" width="1280" height="198" position="flex-start" alt="Okta - Create App Integration" showCaption="false"}
:::

:::WorkflowBlockItem
Select **SAML 2.0** in the popup winder and click **Next**.

![Okta - SAML 2.0](https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-YM-UtsSzf3VUED6AxqZrL-20250210-120611.png)
:::

:::WorkflowBlockItem
In the **General Settings** tab, name your app and upload your icon.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-Ccy4xYwXpFlMwZjqtLvpL-20250210-135617.png" size="80" width="1280" height="694" position="flex-start" alt="General Settings" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Next**.
:::

:::WorkflowBlockItem
In the **Configure SAML** tab, enter the Single sign-on URL that you copied in the steps to [create your namespace](docId\:Q0SYPMV8_3Mmt_NiKfL2K) above.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-hinxEv_xzreJUvGVmUZrD-20250210-134944.png" size="80" width="1280" height="755" position="flex-start" alt="SAML single sign on settings" showCaption="false"}
:::

:::WorkflowBlockItem
Enter the Audience URI (SP Enttity ID) as `https://www.make.com/sso/saml/{{namespace}}/metadata.xml`.
:::

:::WorkflowBlockItem
Keep the **Default Relay State** blank.
:::

:::WorkflowBlockItem
Enter the following information:

| **Field**                      | **Value**         |
| ------------------------------ | ----------------- |
| Name ID format                 | EmailAddress      |
| Application Username           | Okta username     |
| Update application username on | Create and update |


:::

:::WorkflowBlockItem
Click **Show Advanced Settings**.
:::

:::WorkflowBlockItem
Verify that all of the information provided matches the following:

![Advanced settings](https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-peiF1UzXhPIWrbB3jqDm7-20250210-124821.png)

Set **Assertion Encryption** to **Encrypted**. For the Signature Certificate field, upload the Make [Service Provider Certificate](docId\:Q0SYPMV8_3Mmt_NiKfL2K)  you downloaded above.
:::

:::WorkflowBlockItem
Under **Attibute Statements (optional)**, add the attribute as shown in the image and click **Next** to save.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-SiQbDIa-JShNXnnDKXv5I-20250210-130651.png" size="80" width="1280" height="684" position="flex-start" alt="optional attributes" showCaption="false"}
:::

:::WorkflowBlockItem
Select the following options and click **Finish**.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-O8awu-iFAcJ71R18K-B_r-20250210-130411.png" size="80" width="1280" height="1022" position="flex-start" alt="Okta saml final steps" showCaption="false"}
:::

:::WorkflowBlockItem
Assign people to your Make application under the **Assignments** tab in Okta.
:::

:::WorkflowBlockItem
Under the **Sign On** tab in Okta, view the SAML setup instructions.&#x20;
:::

:::WorkflowBlockItem
Copy the **Identity Provider Single Sign-On URL** and the **Identify provider certficate** and save them in a safe place.
:::

:::WorkflowBlockItem
In Make, under **Organization > SSO**, update the **IdP log URL** field and the **Identify provider certficate** field with the information obtained in Okta in step 16.&#x20;
:::

:::WorkflowBlockItem
Enter the following in the **Login IML resolve** field:

```text
{"email":"{{get(user.attributes.email, 1)}}","name":"{{get(user.attributes.profileFirstName, 1)}}{{get(user.attributes.profileLastName, 1)}}","id":"{{user.name_id}}"}
```
:::

:::WorkflowBlockItem
Set:

- **Allow Unecrypted Assertions** to **No**
- **Allow Unsigned Responses** to **No**
- **Sign Requests** to **Yes**
:::

:::WorkflowBlockItem
Select the team and **Save**.
:::
::::

Once saved, the page will reload. Sign out.

:::hint{type="info"}
You will receive an email with the subject **Activation complete: SSO ready for your organization** upon successful activation. If you encounter any issues while logging in using SSO, disable SSO using the "one-time link" (valid for 24 hours).&#x20;
:::

## Service Provider initiated SSO

1. Go to [make.com](https://make.com).&#x20;
2. Click **Sign in with SSO**.
3. Enter the namespace you chose for your organization.
4. Log in using your Okta credentials and consent to Make's access to your user data.

