# Okta

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > SAML). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/saml-sso/okta
Last updated: 2026-10-03

Configure Okta as a SAML identity provider for NocoDB.

This article gives the steps to configure Okta as the identity provider for NocoDB.

### NocoDB, Retrieve `SAML SSO` Configuration details

1. Go to `Account Settings`.
2. Select `Authentication (SSO)`.
3. Click the `New Provider` button.
4. In the dialog, type a `Display name` for the provider. The login page shows the provider with this name.
5. Copy the `Redirect URL` & `Audience / Entity ID`. You need these values later to configure the identity provider.

<img alt="SAML SSO Configuration" src={__img0} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img1} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img2} placeholder="blur" />

### Okta, Configure NocoDB as an Application

1. Sign in to your [Okta account](https://www.okta.com/).
   * Go to `Applications` > `Applications`.
   * Click `Create App Integration`.
2. The `Create a new app integration` dialog opens. For the Sign-in method, select `SAML 2.0`.
3. On the `Create SAML Integration` page, in the General settings, type a name for your app. Click `Next`.
4. In the `Configure SAML` section:
   * In the `Single sign-on URL` field, enter the `Redirect URL` from NocoDB.
   * In the `Audience URI (SP Entity ID)` field, enter the `Audience URI` from NocoDB.
   * From the `Name ID format` options, select `Email Address`.
   * From the `Application user-name` options, select `Email`.
   * Click `Next`.
5. In the final step, complete any additional information. Click `Finish`.
6. On your application's homepage:
   * Go to the `Sign-on` tab.
   * From the `SAML 2.0` section, copy the `Metadata URL`.
7. Go to the `Assignments` tab. Click `Assign` to assign people or groups to this application.

### NocoDB, Configure Okta as an Identity Provider

1. Go to `Account Settings` > `Authentication (SSO)` > `SAML`.
2. In the "Register SAML Identity Provider" dialog, enter the `Metadata URL` from the step above. You can also configure the XML directly.
3. Click `Save`.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

Users now see the `Sign in with <SSO>` option on the sign-in page.

<img alt="SAML SSO Configuration" src={__img4} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* SAML SSO is available on **NocoDB Cloud** (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach [**out to sales team**](https://cal.com/nocodb/sales).
* On the **Business plan**, the SSO configuration menu is in the workspace sidebar, at **Settings** > **Single Sign-On (SSO)**. For more details, refer [here](/docs/product/account-settings/authentication#business-plan).
* **Domain Verification Required for Cloud Plans**: Verify your domain in NocoDB before you configure SAML SSO. Cloud Business and Enterprise plans both need this. Only users with email addresses from verified domains can sign in with SSO. For details, see [Domain Verification](/docs/product/account-settings/authentication#domain-verification).

---

## Related pages

- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/auth0.md): Configure Auth0 as a SAML identity provider for NocoDB.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/ping-identity.md): Configure Ping Identity as a SAML identity provider for NocoDB.
- [Azure AD (Entra)](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/azure-ad.md): Configure Active Directory (Azure AD, Entra) as a SAML identity provider for NocoDB.
