Skip to main content

How to configure Short.io SSO via Okta

Short.io supports Organization SSO (Single Sign-On) integration with Okta.

Note

The SSO configuration is available on the Enterprise Plan.

SSO login video demo



Configuring Short.io SSO with Okta

Before you begin

You need to create and enable a SAML configuration in Short.io before setting up SSO with Okta.

Follow these steps:

  1. From Short.io's left panel, expand the Organizations settings.

  2. Click the icon next to the Organization where you want to configure SAML:

  3. Navigate to the SAML tab:

  4. Click Add SAML configuration.

  5. In the next screen:

    • set Config enabled

    • enter Your SSO configuration name (or your company name)

  6. Copy the ACS URL (this is where you go when you try to log in using SSO) and save it for later:

  7. Save.

Okta settings

  1. Sign in to your Okta account.

  2. Open Admin:

  3. Select Applications > Applications:

  4. Click Create App Integration.

  5. Select SAML 2.0 :

  6. Click Next:

  7. Enter an app name of your choice:

  8. Click Next

  9. In the Single sign-on URL field of the subsequent screen paste the following link where you substitute <yourcompanyname> with Your SSO configuration name:

    https://authorizer.short.io/auth/saml/<yourcompanyname>

  10. Scroll down to click Next.

  11. In the Feedback screen click Finish.

  12. Open the app and navigate to the Sign On tab:

  13. Click View SAML Setup Instructions.

  14. From the next screen:

    • copy and save the Identity Provider Single Sign-On URL

    • copy and save the Identity Provider Issuer

    • download the X.509 certificate on your device

Short.io settings

  1. From the Organization SAML settings tab, open the configuration by clicking :

  2. In the next screen:

  3. Optionally, you can add members to sign in to a team using this SSO configuration. Expand the list and select one of the teams:

  4. Optionally, you can map SAML attributes in your identity provider to control how members are provisioned when they sign in. Here is the list of available settings:

  5. Expand the Advanced options where you can:

    • add an extra layer of security with Sign auth request enabled

    • specify which RequestedAuthContext Short.io should send in authentication requests to your identity provider (select one from the list) - Password, Kerberos, X.509, TLS or FederationAuthWindows

    • define whether the Response and Assertions should be signed

    • enable profile update each time users log in

    • allow users to choose their own display name

    • specify whether SSO is optional or is required for all members of the Organization:

  6. Save.

Note

The Short.io team configures SSO within 24 hours.

In case you need further assistance, please contact the Short.io support team at [email protected].

First-time logging in with SSO

With the SAML configuration set up, your Organization members can use the Short.io's ACS URL or the page https://app.short.io/public/login (button SSO) to log in.

Short.io automatically creates a SAML-based login in the given Organization with the role Member for each user who logs in via SSO for the first time:

In case you have added a user without specifying a team, the Organization admin(s) should grant this user access to the resources they are authorized to use:

Otherwise, when team members log in through SSO, they are redirected to the dashboards and settings they usually have permission to access.