Single Sign-On With Okta
Requirements
- You will need to be the
Adminof the Statsig Organization you intend to add SSO with Okta to. - You will need to be the Administrator of the Okta account you want to link.
Supported Features
Service Provider(SP)-Initiated Authentication for Single Sign-On (SSO) using OIDC can be enabled on Statsig to connect your Okta account to your Statsig Projects.
Configuration
Adding the Statsig OIDC Application in Okta
- Navigate to your Okta portal.
- On your Okta portal, click on
Applicationson the left-hand-column, and click intoApplicationsin the dropdown.
- On the Applications page, click on the
Browse App Catalogbutton.
- On the App Catalog page, use the searchbox to search for Statsig and click on the Statsig OIDC Application.
- In the Statsig Application, click on the
Addbutton.
- After creating the Statsig OIDC Application in Okta, navigate to the
Sign Ontab in the Application, note theClient IDandClient Secretfields that will be needed to enable Single Sign-On with OIDC on the Statsig Project.
Once these steps have been completed, the Statsig OIDC Application in Okta has been successfully configured. Following this, you will need to follow the steps here to enable configuration of SSO on your Statsig Project.
Note when adding the Statsig OIDC Application in Okta, the sign-in and sign-out redirect URIs are automatically configured.
Proof Key for Code Exchange (PKCE)
Statsig does not currently support the PKCE Flow, so you will need to turn off the feature in Okta when you enable SSO with Statsig.