Okta

This page gives the steps to configure Okta as the Identity service provider for NocoDB.

NocoDB, Retrieve Redirect URL

  1. Go to Account Settings.
  2. Select Authentication (SSO).
  3. Click the New Provider button. A popup modal opens.
  4. In the popup modal, specify a Display name for the provider. The login page shows the provider with this name.
  5. Copy the Redirect URL. You configure it later in the Identity Provider.

OIDC SSO Configuration OIDC SSO Configuration OIDC SSO Configuration

Okta, Configure NocoDB as an Application

  1. Sign in to your Okta account. Go to the "Get started with Okta" page.
    • For the Single Sign-On option, click Add App.
    • On the Browse App Integration Catalog page, select Create New App.
  2. In the Create a new app integration pop-up:
    • Select OIDC - OpenID Connect as the Sign-in method.
    • Select Web Application as the Application type.
  3. On the New Web App Integration page, go to General Settings.
    • Type the name of your application.
    • In the Grant type allowed section, select Authorization Code and Refresh Token.
    • Below Sign-in redirect URIs, add the Redirect URL.
    • In the Assignments section, select an option from Controlled access. This option sets who can access this application.
    • Click Save.
  4. In your new application:
    • Go to the General tab.
    • Copy the Client ID and Client Secret from the Client Credentials section.
  5. In the navigation bar, open the Account dropdown.
    • Copy the Okta Domain.
  6. Add "./well-known/openid-configuration" to the end of the Okta Domain URL. Open this URL.

NocoDB, Configure Okta as an Identity Provider

In NocoDB, open Account Settings > Authentication > OIDC. The "Register OIDC Identity Provider" modal opens. Enter this information:

NocoDB fieldValue
Client IDThe Client ID from step (6) above
Client SecretThe Client Secret from step (6) above
Authorization URLThe authorization_endpoint from step (8) above
Token URLThe token_endpoint from step (8) above
Userinfo URLThe userinfo_endpoint from step (8) above
JWK Set URLThe jwks_uri from step (8) above
Scopeopenid profile email offline_access
Username AttributeThe name of the claim that holds the email of the user. The default value is "email."

The sign-in page now shows the Sign in with <SSO> option to users.

SAML SSO Configuration

Post sign-out, refresh page (for the first time) if you do not see Sign in with SSO option

For information about Okta API Scopes, refer here.

For more common questions and troubleshooting, see our SSO FAQ.

Availability

  • OIDC SSO is available on NocoDB Cloud (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach out to sales team.
  • For users on the Business plan, the SSO configuration menu is in the workspace sidebar, at Settings > Single Sign-On (SSO). For more information, refer here.
  • Domain Verification Required for Cloud Plans: Before you configure OIDC SSO, you must verify your domain in NocoDB. This is necessary for both Business and Enterprise plans in the cloud. Only users with email addresses from verified domains can sign in through SSO. For more information, refer to Domain Verification.

Last updated on

Latest product updates?See Changelog
Stay in the loop? Follow us onLinkedInLinkedInYouTubeYouTubeXX