Skip to main content

Okta

Configure Okta Integration using SAML​

Follow these steps to configure the Okta Integration for your Levo organization. This will allow you to use Okta to login to the platform.

  1. Navigate to User Settings > Organizations in the Levo Dashboard. Select your organization and navigate to the SSO tab. Click on Configure SSO and then select Okta.
  2. Copy the Assertion Consumer Service URL (ACS URL) and Entity ID. These will be used during the Okta app creation.
caution

Copy both values after you have entered your Domain in the Levo form. The ACS URL is derived from the domain, so copying it earlier gives you a URL that will not work.

  1. In your Okta admin console, go to Applications > Applications and click Create App Integration.

  2. Select SAML 2.0 as the sign-in method and click Next.

  3. On General Settings, set the App name and click Next.

  4. On Configure SAML, set Single sign-on URL to the ACS URL and Audience URI (SP Entity ID) to the Entity ID you copied in step 2, leaving Use this for Recipient URL and Destination URL checked. Leave Default RelayState empty, set Name ID format to EmailAddress and Application username to Email, and leave the remaining signature and certificate settings at their defaults.

  5. Still on Configure SAML, scroll to Attribute Statements and add email with the value user.email, userFirstName with the value user.firstName, and userLastName with the value user.lastName. Leave Name format as Unspecified for all three.

note

If the Attribute Statements section does not appear in the wizard, finish creating the app and add them afterwards under General > SAML Settings > Edit, or under Sign On > Attribute statements > Show legacy configuration.

  1. Click Next, choose I'm an Okta customer adding an internal app and click Finish.

  2. Under the Assignments tab, click Assign > Assign to People and assign the users who should be able to sign in to Levo.

    Only users that already exist in your Okta directory can be assigned. To add one, go to Directory > People > Add Person.

    Users who are not assigned are blocked by Okta before Levo is ever reached.

  3. (Optional) Edit the logo of the application and replace it with the Levo logo so you can identify it in your Okta dashboard.

  4. Go to Sign On > SAML 2.0 > Metadata details and copy the Metadata URL.

  5. Go back to Levo and fill in the details to connect your Okta app:

    • Connection Name: An identifier for the connection.
    • Okta Metadata URL: The Metadata URL you copied from Okta.

After that, users on that email domain can sign in to Levo using Okta.

Add a Levo tile to the Okta dashboard​

Levo starts the SAML exchange itself, so sign-in must begin at Levo. Clicking the SAML app's tile on the Okta dashboard starts it from Okta instead, which Levo does not accept — it fails with "Unexpected error when authenticating with identity provider".

To give users a working tile, add a Bookmark App that points at Levo:

  1. Go to Applications > Applications > Browse App Catalog and search for Bookmark App, then click Add integration.
  2. Set Application label to Levo and URL to https://app.levo.ai.
  3. Click Done, then open the Assignments tab and assign the same users.
  4. (Recommended) In the SAML app's General settings, enable Do not display application icon to users so people are not offered the tile that cannot work.

Clicking the bookmark tile opens Levo, which then redirects to Okta and signs the user straight in.

Signing in​

  • Go to https://app.levo.ai and enter your work email address. Levo recognises the domain and redirects you to Okta.
  • Or click the Levo bookmark tile on your Okta dashboard.

Users who already have a Levo account are asked once to confirm the link between it and their Okta identity. Subsequent logins go straight through.

Was this page helpful?