SSO with Okta
Last updated: 2 September 2026
Certyneo supports Single Sign-On with Okta, allowing your team members to sign in to their Certyneo workspace using their existing Okta credentials, with no additional password to manage.
1. Prerequisites
SSO is available on Certyneo's Business and Enterprise plans. You must be an administrator of your Certyneo workspace to start the configuration, and hold the necessary admin rights on the Okta side to create a SAML 2.0 or OpenID Connect application.
2. Supported features
- SP-initiated SSO from Certyneo, via SAML 2.0 or OpenID Connect
- Automatic account provisioning on first sign-in (Just-In-Time provisioning)
- IdP-initiated SSO from Okta
When a sign-in starts from Okta, Certyneo first shows a confirmation screen naming the account involved; the user confirms before the session opens. This step protects your team from being signed in, without realising it, to an account that isn't theirs.
SP-initiated Single Logout (SLO) from Certyneo isn't available yet.
3. Configuration steps
- In your Certyneo admin workspace, go to Settings → Workspaces and click "Configure SSO".
- You're taken to our identity partner's secure setup portal. Select “Okta” as your identity provider.
- The portal shows your ACS URL and your entity ID (SP Entity ID). Make a note of that entity ID — it's your “Certyneo SSO connection ID”. It's also the last part of the ACS URL, after the final “/”. Keep this tab open; you'll come back to it at step 5.
- In your Okta Admin Console, add the “Certyneo” app from the Okta catalog, then fill in the “Certyneo SSO connection ID” field with the identifier you noted in the previous step.
- Still in Okta, copy the app's SAML metadata URL, then paste it back into the setup portal.
- SSO is live: your team can now sign in through “Sign in with your company SSO” on the Certyneo sign-in page.
Would rather not use the Okta catalog? You can create the SAML 2.0 or OpenID Connect app yourself. The “Certyneo SSO connection ID” isn't asked for in that case: just copy the ACS URL and entity ID shown at step 3 straight into your Okta app.
4. Troubleshooting
If sign-in fails, verify that the user exists with the same email address on both Okta and Certyneo, and that the Okta application is properly assigned to the user or their group.
For any assistance configuring SSO, contact us at contact@certyneo.com.