Skip to main content

Okta configuration

How to set up SAML for your Survicate account

Written by Vlada

This article will guide you through enabling Okta configuration in your account.

SAML SSO gives users a centralized and secure way of controlling access to their organizations. When you join an organization that uses SAML SSO, you sign in through the organization's IdP, and your existing Survicate account is linked to an external identity that belongs to the organization.

❗️This feature is available on some of our plans. Please check out our Pricing page for more information or talk to us on chat 👉.

How to enable Okta configuration?

❗Before you start, you need to ensure you are your organization's owner. Only account owners can set up SAML Authentication.

Please go to Settings ➡️ SAML Authentication and click the Enable SAML authentication toggle. Leave the tab open, as you'll need the data from here:

Okta - Identity Provider (IdP) setup

1. In your Okta account, go to the Admin Console ➡️ Applications and choose Create App Integration:

2. Choose SAML 2.0 and click Next:

3. In the General Settings step, add the app's name and, optionally, the logo, then click Next:

4. In the Configure SAML step, you have to fill in the Single sign-on URL and the  Audience URI (SP Entity ID).

  • Single sign-on URL can be copied directly from Survicate; it's the ASC (Consumer) URL that you can find here:

  • Audience URI (SP Entity ID) is the same URL, but it has a different ending with /metadata instead of /acs.

    So if your Single sign-on URL is:

    https://panel-api.survicate.com/settings/saml/1234/acs

    Your Audience URI (SP Entity ID) will be:

    https://panel-api.survicate.com/settings/saml/1234/metadata

5. Once it's done, your settings should look like this:

6. On the bottom of the screen, click Next and then, in the next screen, Finish.

7. In the next screen, in the Sign On tab, click View SAML setup instructions:

Once the page opens, you'll see your Identity Provider Single Sign-On URL, Identity Provider Issuer, and X.509 Certificate:

Survicate setup

1. In the Survicate SAML Authentication tab, paste:

  • The Identity Provider Single Sign-On URL to the Sign on URL field;

  • The Identity Provider Issuer to the Issuer field;

  • The X.509 Certificate to the Public certificate field:

Then confirm by clicking Save configuration.

Once you click Save configuration, you'll see a list of recovery codes. ❗ Make sure to save them, so you can access your account in case you lose access to your SAML.

Passwordless authentication

You can set up a requirement teammates to use their passwords additionally to login to the Survicate account, or opt for a frictionless process, by switching on this option:

Thanks to this feature, by default, all new users, who use SAML won't be required to provide the password to log in to Survicate.

Enforce SAML Login for everyone in the organization

This option will become available after SAML is successfully configured and the Survicate account's first SAML login occurs. It lets you ensure that all teammates will be able to use SAML to log in

Grant access to all workspaces when inviting users through SSO

If you choose to enable this option and your Survicate organization has multiple workspaces, all new teammates you invite to your account will automatically gain access to all workspaces.

Logging in

Please note that during the first login via SSO, once you finish the SSO login, you'll have to log in one more time via password or Google (the way you previously used) to complete the SSO setup:

Now, with SAML enabled, to avoid using your login and password on the Survicate login page, you can log in directly from your Okta Sign on URL. Once you sign in via SSO, and Passwordless authentication is enabled, you will not be asked for your Survicate password.

Alternatively, if you're already authenticated via your SSO provider, you can click Log in with SSO on the Survicate login page:

📞 If you have any questions or need assistance - feel free to reach out to our team via chat or email: support@survicate.com.

Did this answer your question?