> For the complete documentation index, see [llms.txt](https://docs.rely.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.rely.io/security-and-compliance/single-sign-on-sso/oidc-with-okta.md).

# OIDC with Okta

This guide will help you enable SSO from your Okta so your users can securely log into Rely.io without creating new credentials.

{% hint style="info" %}
This process can only be fully achieved in collaboration with our team.&#x20;

Exact instructions are provided in the impacted sections below where this exchange of information is required.
{% endhint %}

## Create a new OIDC application in the Okta Admin Console

1. Sign-in to your Okta Admin Console.
2. On the sidebar, navigate to **Applications** -> **Applications**
3. On the main view, click the "Create App Integration" button

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FW0e20KxOVI6ffDFuGI0R%2Fimage.png?alt=media&amp;token=fa934f86-3dae-4867-94a3-206ed7d0e899" alt=""><figcaption></figcaption></figure>

4. In the Modal Dialog, select **OIDC - OpenID Connect**

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FnkOrCxMdOnbbPhR4tDnn%2Fimage.png?alt=media&amp;token=357de5ad-8c1d-4dfa-95e2-2e6897d3948a" alt=""><figcaption></figcaption></figure>

5. Choose **Single-Page application** as your application type and click **Next\\**

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FtxWAfSffmGQmzyw5inT2%2Fimage.png?alt=media&amp;token=f4347416-89f6-47ce-87aa-cde716cd100a" alt=""><figcaption></figcaption></figure>

## Configure OIDC Application&#x20;

### Under the General Settings tab

1. Choose the name of the connection (that name will appear on your Okta apps)
2. Add application logo (optional)&#x20;
3. Under **Grant type,** mark all options

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FNky0M2ggjLp8vjvYfonB%2Fimage.png?alt=media&amp;token=f930829c-b534-463d-8d01-a3b14413f208" alt=""><figcaption></figcaption></figure>

4. Under **Sign-in redirect URIs** set [`https://auth.rely.io/login/callback` ](<https://auth.rely.io/login/callback >)

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FFyZbgoH9Tvbc4LhI4TDk%2Fimage.png?alt=media&amp;token=ac40087e-b2eb-4bae-9a7d-93b1a071207f" alt=""><figcaption></figcaption></figure>

4. Remove the sign-out redirect URIs.
5. Under **Assignments** set `Allow everyone in you organization to access`
6. Check `Enable immediate access with`` `**`Federation Broker Mode`** (optional)

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FxHO49jHPIUCrWy0OdxhB%2Fimage.png?alt=media&amp;token=62894ba7-3909-4c02-969b-4f400a4d6080" alt=""><figcaption></figcaption></figure>

## Configure your App OIDC settings and share your connection data with Rely

{% hint style="info" %}
You can share the data using one of our dedicated channels:

* Direct outreach to your dedicated Customer Success Manager
* In Slack via your Dedicated Channel (for Enterprise customers)
* Via your in-product chatbot
* Via email to <support@rely.io>
  {% endhint %}

### Get Okta Domain to share with Rely

Retrieve the **Okta Domain** by clicking on your user email at the top-right corner of the Okta management interface and copy to clipboard the Okta domain. (The format should be `{YOUR_COMPANY_NAME}.okta.com` )

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FRVPyGGZvuaHjf7OpLsyi%2Fimage.png?alt=media&amp;token=6aa623b1-494c-4d54-adb8-14fd5ec9982f" alt=""><figcaption></figcaption></figure>

Share the domain with Rely via dedicated channel.

### Get Client ID to share with Rely.

The next step is to retrieve the **Client ID**. This ID is the unique identifier of your Okta app and is required for Rely to establish an SSO connection.&#x20;

Under the **General** tab, copy the **Client ID,** and share it with Rely via a dedicated channel

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FFKQ7NROgov6kvUPNwABw%2FScreenshot%202024-10-04%20at%2012.22.12.png?alt=media&amp;token=513bed2c-3e95-4f52-bc6d-187990058d24" alt=""><figcaption></figcaption></figure>

### Configure OIDC app

1. Under **General** tab, click on **Edit** button:
2. Set **Login initiated by** to `Either Okta or App`
3. Check the **Login flow** to `Redirect to app to initiate login (OIDC Compliant)`
4. Under I**nitiate login URI,** set the following URI:[`https://auth.rely.io/login?response_type=token&client_id=WwUGI5XuLR2BX3Qh1Z9R6PG2XxTUgtM4&connection={CONNECTION_NAME}&redirect_uri=webapp.rely.io`](<https://auth.rely.io/login?response_type=token\&client_id=WwUGI5XuLR2BX3Qh1Z9R6PG2XxTUgtM4\&connection=okta-prod-test\&redirect_uri=webapp.rely.io >)

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FjDySpYaYdMi0sy3WmvhF%2Fimage.png?alt=media&amp;token=48a696f0-1483-4557-a2f8-2f46c23c05d7" alt=""><figcaption></figcaption></figure>

5. Click **Save.** Now you have your Okta OIDC app connection to Rely.
