Single Sign-On With Okta
Requirements
- You will need to be the
Admin
of the Statsig Organization you intend to add SSO with Okta to. - You will need to be the Administrator of the Okta account you want to link.
Supported Features
Service Provider(SP)-Initiated Authentication for Single Sign-On (SSO) using OIDC can be enabled on Statsig to connect your Okta account to your Statsig Projects.
Configuration
Adding the Statsig OIDC Application in Okta
- Navigate to your Okta portal.
- On your Okta portal, click on
Applications
on the left-hand-column, and click intoApplications
in the dropdown. - On the Applications page, click on the
Browse App Catalog
button. - On the App Catalog page, use the searchbox to search for Statsig and click on the Statsig OIDC Application.
- In the Statsig Application, click on the
Add
button. - After creating the Statsig OIDC Application in Okta, navigate to the
Sign On
tab in the Application, note theClient ID
andClient Secret
fields that will be needed to enable Single Sign-On with OIDC on the Statsig Project.
Once these steps have been completed, the Statsig OIDC Application in Okta has been successfully configured. Following this, you will need to follow the steps here to enable configuration of SSO on your Statsig Project.
Note when adding the Statsig OIDC Application in Okta, the sign-in and sign-out redirect URIs are automatically configured.
Proof Key for Code Exchange (PKCE)
Statsig does not currently support the PKCE Flow, so you will need to turn off the feature in Okta when you enable SSO with Statsig.