> For the complete documentation index, see [llms.txt](https://docs.devarmor.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.devarmor.com/getting-started/single-sign-on-sso-authentication/okta-sso-oin-catalog.md).

# Okta SSO (OIN Catalog)

### Prerequisites

* A **DevArmor organization account**. If your company doesn't have one, sign up at [https://devarmor.com](https://devarmor.com/) or contact your DevArmor representative.
* **Administrator** access to your Okta org.
* DevArmor enables Okta SSO **per organization**. You'll share your integration details with DevArmor in the steps below; DevArmor activates SSO for your organization, typically within **one business day**.

### Supported features

* **SP-initiated SSO**: users start sign-in from the DevArmor application.

Not supported:

* IdP-initiated SSO (Third-party Initiated Login)
* Just-In-Time (JIT) provisioning — DevArmor provisions users on its side
* Single Logout (SLO)

*(See the* [*Okta Glossary*](https://help.okta.com/oie/en-us/content/topics/glossary.htm) *for feature definitions.)*

### Configuration steps (Okta administrator)

1. In the Okta Admin Console, go to **Applications → Applications → Browse App Catalog**.
2. Search for **DevArmor** and click **Add Integration**.
3. On **General Settings**, enter an application label and click **Done**.
4. Open the **Sign On** tab and copy the **Client ID** and **Client Secret**.
5. On the **Assignments** tab, assign the integration to the users or groups who should access DevArmor.
6. Send the following to DevArmor at [**integrations@devarmor.com**](mailto:integrations@devarmor.com) (see [our guide for a secure transfer](/getting-started/single-sign-on-sso-authentication/encrypting-credentials-for-devarmor.md)):
   * Your **Okta org domain** (for example, `yourcompany.okta.com`)
   * The **Client ID** and **Client Secret** from step 4
   * The **email domain(s)** your users sign in with (for example, `yourcompany.com`)
7. DevArmor enables SSO routing for your organization and confirms by email.

**Application username format:** email.

### SP-initiated SSO (end users)

1. From your browser, navigate to the DevArmor sign-in page at [**https://app.devarmor.com/sign-in**](https://app.devarmor.com/sign-in).
2. Click **Sign in with Okta** and enter your work email address.
3. You're redirected to your Okta organization to authenticate with your Okta credentials.
4. After successful authentication, you're redirected to the DevArmor dashboard.

### Support

* **Support email:** <support@devarmor.com>
* **Documentation:** [https://docs.devarmor.com](https://docs.devarmor.com/)

<br>
