# Okta

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > OpenID Connect). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/okta
Last updated: 2026-10-03

Configure Okta as an OIDC identity provider for NocoDB SSO.

This page gives the steps to configure Okta as the Identity service provider for NocoDB.

### NocoDB, Retrieve `Redirect URL`

1. Go to `Account Settings`.
2. Select `Authentication (SSO)`.
3. Click the `New Provider` button. A popup modal opens.
4. In the popup modal, specify a `Display name` for the provider. The login page shows the provider with this name.
5. Copy the `Redirect URL`. You configure it later in the Identity Provider.

<img alt="OIDC SSO Configuration" src={__img0} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img1} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img2} placeholder="blur" />

### Okta, Configure NocoDB as an Application

1. Sign in to your [Okta account](https://www.okta.com/). Go to the "Get started with Okta" page.
   * For the Single Sign-On option, click `Add App`.
   * On the `Browse App Integration Catalog` page, select `Create New App`.
2. In the `Create a new app integration` pop-up:
   * Select `OIDC - OpenID Connect` as the Sign-in method.
   * Select `Web Application` as the Application type.
3. On the `New Web App Integration` page, go to `General Settings`.
   * Type the name of your application.
   * In the `Grant type allowed` section, select `Authorization Code` and `Refresh Token`.
   * Below `Sign-in redirect URIs`, add the `Redirect URL`.
   * In the `Assignments section`, select an option from `Controlled access`. This option sets who can access this application.
   * Click `Save`.
4. In your new application:
   * Go to the `General` tab.
   * Copy the `Client ID` and `Client Secret` from the `Client Credentials` section.
5. In the navigation bar, open the `Account` dropdown.
   * Copy the `Okta Domain`.
6. Add "./well-known/openid-configuration" to the end of the `Okta Domain` URL. Open this URL.
   * Example: [https://dev-123456.okta.com/.well-known/openid-configuration](https://dev-123456.okta.com/.well-known/openid-configuration)
   * From the JSON response, copy `authorization_endpoint`, `token_endpoint`, `userinfo_endpoint` and `jwks_uri`.

### NocoDB, Configure Okta as an Identity Provider

In NocoDB, open `Account Settings` > `Authentication` > `OIDC`. The "Register OIDC Identity Provider" modal opens. Enter this information:

| NocoDB field        | Value                                                                                 |
| ------------------- | ------------------------------------------------------------------------------------- |
| `Client ID`         | The `Client ID` from step (6) above                                                   |
| `Client Secret`     | The `Client Secret` from step (6) above                                               |
| `Authorization URL` | The `authorization_endpoint` from step (8) above                                      |
| `Token URL`         | The `token_endpoint` from step (8) above                                              |
| `Userinfo URL`      | The `userinfo_endpoint` from step (8) above                                           |
| `JWK Set URL`       | The `jwks_uri` from step (8) above                                                    |
| `Scope`             | `openid` `profile` `email` `offline_access`                                           |
| Username Attribute  | The name of the claim that holds the email of the user. The default value is "email." |

The sign-in page now shows the `Sign in with <SSO>` option to users.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

For information about Okta API Scopes, refer [here](https://developer.okta.com/docs/reference/api/oidc/#scopes).

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* OIDC SSO is available on **NocoDB Cloud** (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach [**out to sales team**](https://cal.com/nocodb/sales).
* For users on the **Business plan**, the SSO configuration menu is in the workspace sidebar, at **Settings** > **Single Sign-On (SSO)**. For more information, refer [here](/docs/product/account-settings/authentication#business-plan).
* **Domain Verification Required for Cloud Plans**: Before you configure OIDC SSO, you must verify your domain in NocoDB. This is necessary for both Business and Enterprise plans in the cloud. Only users with email addresses from verified domains can sign in through SSO. For more information, refer to [Domain Verification](/docs/product/account-settings/authentication#domain-verification).

---

## Related pages

- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/auth0.md): Configure Auth0 as an OIDC identity provider for NocoDB SSO.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/ping-identity.md): Configure Ping Identity as an OIDC identity provider for NocoDB.
- [Azure AD (Entra)](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/azure-ad.md): Configure Azure AD as an OIDC identity provider for NocoDB SSO.
