> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://central.baseb.app/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Okta SSO Integration

If your organization uses Okta to manage your employees access to tools and services, you can take advantage of Okta’s “Single Sign-On” feature that allow users to enter one name and password to access multiple applications, including Base-B.

The integration between Okta and Base-B that enables this SSO to occur is built around an industry-standard protocol known as SAML (Security Assertion Markup Language). To learn more about how Okta works with SAML, [please see this article](https://www.okta.com/blog/2020/09/what-is-saml/).

The remainder of this guide is focused on enabling you to configure both Base-B and Okta to get provisioning up and running for your organization.

# Contents

* Features
* Requirements
* Configuration Steps
* Known Issues/Troubleshooting

# Features

The following provisioning features are supported:

* **IdP-initiated SSO: **Identity Provider-initiated Single Sign-On. A single sign-on operation that was started from the IdP Security Domain. The IdP federation server creates a federation SSO response and redirects the user to the SP with the response message and an optional operational state.

# Requirements

SAML single sign-on are only available to paying customers.

# Configuration Steps

Configure single sign-on as follows.

### Enable single sign-on functionality

###### In Okta

1. In the OKTA administrative panel, in Applications > Applications, browse the app catalog and search for the "Base-B" app. After finding it, select the application and click "Add Integration"

![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/image_e8su42.png)

2. In General Settings, fill in the Base URL field with the value "https://api.baseb.app" for the production environment or "https://api.baseb.xyz" for the homologation environment, and click "Done".

![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/image_1dbtbh8.png)

3. In the OKTA administrative panel, in Applications > Applications, access the Base-B application recently added and go to the "General" tab.

![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/image_159x2lc.png)

4. In the "App Embed Link" area, copy your company's Okta url, this value will be used later:

![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/image_m13sle.png)

5. In the "Sign On" tab of the Base-B application in Okta, view and copy the certificate (only the content of the ds:X509Certificate tag), this value will be used later:

![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/lqgqxmdugk_lhgpjw.png)
![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/uirxa42csd_vnqsv7.png)

###### In Base-B

1. In Settings > Integrations > Applications, enable the Okta integration:

![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/image_1gsmjje.png)

2. Fill in the fields according to the information previously obtained and set the audience field to the value "baseb", see the example in the following image:

![](https://storage.crisp.chat/users/helpdesk/website/9040e83e46dad000/image_13tju7h.png)

That's it, the integration with Okta is complete.

# Known Issues/Troubleshooting

If you have questions or difficulties with your Base-B/Okta SSO integration, please contact Base-B support via **suporte@baseb.com.br**