Before you start
- An Operata account with admin permissions.
- Admin access to an OIDC IdP.
- The email domains your users sign in with, such as
acme.com. - The users who need access, and the Operata group each one belongs to.
email claim. Release email_verified as well if your IdP supports it.
Steps
1. Request SSO from Operata
Email Operata Support or your Customer Success Manager. Include your email domains and the users, each with their Operata group.2. Create a web application in your IdP
Create an OIDC web application with these settings:
Register both sign-in redirect URIs. Assign the application to the users who need access.
3. Release the email claims
Configure the application to releaseemail, and email_verified if available. The email must match the user’s Operata account. Matching ignores case.
4. Send the connection details to Operata
Reply to the support thread with:- Your issuer or discovery URL, such as
https://acme.okta.com/.well-known/openid-configuration. - The client ID and client secret.
- Confirmation that the application releases
email, and whether it releasesemail_verified.
5. Test sign-in
Test with a user Operata has confirmed. Operata creates each user before their first SSO sign-in, so test only after Operata replies. The user goes tohttps://app.operata.io and enters their work email. Operata redirects them to your IdP. After they authenticate, they land in their Operata account.
Result
Users whose email matches one of your domains sign in athttps://app.operata.io with their corporate credentials. Sign-in starts from that page. OIDC has no equivalent of SAML sign-in from a tile in your IdP dashboard.
Troubleshooting
Related
- Request SSO for your Operata account — SSO through a SAML 2.0 IdP.
- Configure Okta as an SSO identity provider — SAML 2.0 setup in Okta.