RIVET SSO: Okta

Utilize SSO Functionality with RIVET

Identity Provider (IdP) Setup

These are instructions for setting up Rivet SAML SSO with Okta. While setting up your SSO connection it would be best to keep your Okta portal tab and Rivet Security tab open for easy navigation back and forth.

Step 1: Create a new Okta application for RIVET

  1. In RIVET, go to Manage Org using the settings gear in the top right, then select the Security tab

  2. In the Identity Provider section click Okta from the dropdown

  3. Sign in to the Okta portal. On the left navigation pane, select the Applications dropdown

  4. Select Applications

  5. Click New Application

  6. Click Create App Integration

  7. Select SAML 2.0 and click Next

  8. Enter the name of your app (i.e. Rivet Work SSO)

  9. Click Next

    1. Add the Single sign-on URL (copied from the Reply URL field in Rivet): **https://api.rivet.work/auth/okta/sso**
    2. Add Audience URI field (Copied from the Entity ID field in Rivet): https://api.rivet.work/auth/signin/saml

      Under SAML Settings - Enter the following fields:


Step 2: Enter SAML SSO Settings in Rivet

  1. In RIVET, go to Manage Org using the settings gear in the top right, then select the Security tab
  2. You will need to enter and save two fields: the IDP XML Metadata Url and the Authorized Domain field.
  3. The IDP XML Metadata URL can be found in Okta, under the Sign-On Tab for the application you just created. There, find the field named Metadata URL.
  4. Copy this url, ****and paste it into the IDP XML Metadata Url field within Rivet.
  5. Next enter your Authorized Domain in Rivet and click Save.

Note: Note: this domain must be unique among all Rivet registered organizations and cannot be a common domain such as gmail, yahoo, outlook, etc…

 

Step 3: Assign users to RIVET

  1. In the Okta portal, select Applications, and then select the Rivet SSO application you just created.
  2. Navigate to the app's Assignments page.
  3. Select the Assign dropdown and and assign all applicable Users and Groups to the RIVET application.

Step 4: Verify the SSO Configuration in RIVET

  1. You’ll see the banner in the RIVET security page instructing you to verify your SSO configuration.

  2. Log out of RIVET

  3. Log back in selecting Use Single Sign-on and utilize your email for your Rivet account under your authorized domain.