Skip to main content

Set up SSO with Okta

Use Okta Single Sign-On to let your team members sign in to Contrast using their existing Okta credentials.

Written by Karim Matrah

Prerequisites

Okta Single Sign-On is available on the Enterprise plan.

You will need administrator access to your Okta organization to configure the integration.

Supported features

Contrast supports:

  • SSO using OpenID Connect (OIDC)

  • Just-in-time (JIT) provisioning: users are automatically created in Contrast when they sign in for the first time

Configuration steps

1. Configure Okta

First, configure the Contrast application in your Okta account.

  1. Install Contrast webinars from the Okta Marketplace.

  2. In your Okta Admin Console, go to Applications and find Contrast webinars.

  3. Open the Assignments tab and assign the users from your team who should have access to Contrast.

  4. Open the Sign On tab.

  5. Copy the following information:

    • Client ID

    • Client Secret

    • Okta domain

    You can find your Okta domain by clicking the button in the top-right corner of your Okta dashboard. Your domain is displayed in the Information modal that appears.

Keep these values handy, you'll need them in the next step.

2. Configure Contrast

Next, add your Okta credentials to your Contrast account.

  1. Sign in to your Contrast account.

  2. Go to Settings → Integrations.

  3. Click the Okta card to open the configuration modal.

  4. Enter the following information:

    • Okta domain

    • Client ID

    • Client Secret

  5. Save your configuration.

Your Okta integration is now configured.

Test the integration

To verify that everything is working correctly:

  1. Enter your work email address (make sure it is the same email address associated with your Okta account).

  2. Click Continue.

  3. You will be redirected to Okta to sign in.

  4. After successfully signing in, you will be redirected to your Contrast dashboard.

If this is the first time the user has signed in to Contrast, their account will be automatically created through just-in-time provisioning.

Did this answer your question?