Configure Okta with Docubee
Note: Service-Provider-initiated SSO is the only SSO implementation supported by Docubee. Identity-Provider-initiated SSO is not offered at this time.
Configuring Okta with Docubee involves the following:
- Creating an app in Okta
- Configuring your app in Okta
- Configuring your Okta credentials in Docubee
- Verifying your app
Create an App in Okta
This document will assume that the Customer’s Admin is aware of how to set up and use Okta, although we will provide some basic information here.
- Docubee does not offer a prebuilt app for Okta, so the Enterprise App must be added via the Create App Integration path.
- Docubee SSO (Single Sign-On) supports only SAML 2.0 apps.
- Users must be assigned to the App in order to have access to Docubee.
Configure your App in Okta
- Copy the following values from Docubee and paste them in Okta:
- Copy the Audience value from Docubee and paste it in the Audience URI (SP Entity ID) field in your Okta app.
- Copy the Assertion Consumer Service (ACS) URL value from Docubee and paste it in the Single sign-on URL field in your Okta app.
- In your Okta app, uncheck Use this for Recipient URL and Destination URL.
- Copy the Recipient URL value from Docubee and paste it in both the Recipient URL and Destination URL fields in Okta.
- In Okta:
- In the Attribute Statements (optional) field, add the following (this is a required value for use with Docubee):
- Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- Name Format: URI Reference
- Value: “user.email”
- Save the app.
- Navigate to the Assignments tab.
- Click Assign and select the relevant assignment choice.
- Assign all users that should have access to Docubee.
- In the Attribute Statements (optional) field, add the following (this is a required value for use with Docubee):
Configure your Okta Credentials in Docubee
In your new Okta App:
- Navigate to the General tab.
- Scroll to the App Embed Link section.
- Copy the Embed Link from Okta and paste it in the Identity Provider Log-in URL field in Docubee.
- Navigate to the Sign On tab.
- Scroll to the SAML Signing Certificates section.
- Click Actions next to the SHA-2 certificate.
- Click Download Certificate and save it somewhere you will remember.
- In the Upload Certificate file picker in Docubee, select your certificate.
- Click UPDATE SSO CONFIGURATION.
Verify your App
- Once both of the above sections have been completed:
- In Docubee, click TEST SSO CONFIGURATION to launch the new Okta modal.
- Log in to Okta.
If everything went well you should see that screen close and a green alert notification on the bottom of the Docubee screen should confirm a successful test.
- When you are ready to require that ALL your users of a given domain logon only with SSO:
-
- In Docubee, enable the toggle for the respective domain and update your config again.
Please Note: if your config is malformed and you have enabled a domain no one will be able to log into your Docubee organization. To ensure continued access we strongly encourage you to test your configuration prior to logging out.
-
Related Information
Configure Single Sign-On
Additional Resources
Need more help getting set up? Contact us for assistance from our customer support team.