This guide explains how to configure your Okta Workforce Identity Cloud to enable single sign-on (SSO) for Supermetrics using SAML 2.0. This allows your team members to access Supermetrics with their enterprise credentials.
For more information, see also Okta's instructions on adding Okta SAML applications.
Before you begin
Before you can configure your Okta Workforce Identity Cloud for logging in to Supermetrics, you need the following:
- An Okta Workforce Identity Cloud account with administrative privileges.
- Supermetrics SAML configuration details (you can get these details by contacting Supermetrics support):
- Assertion Consumer Service URL (ACS URL): The URL where Okta will send the SAML assertion.
- Entity ID: Unique identifier for Supermetrics as a service provider.
Important: Treat the entity ID value as-is and do not change it (such as by adding trailing slashes). While the entity ID looks like a URL, it's a URI and must not be modified.
- Start URL: The URL where users will be redirected after successful authentication.
Instructions
Step 1: Create a new Okta app
- Log in to your Okta admin console.
- Navigate to Applications → Applications.
- Click Create App Integration.
- Select SAML 2.0 as the application sign-on method.
- Give the application a meaningful name, such as "Supermetrics".
- Configure the SAML settings:
- Single sign-on URL: Enter the Assertion Consumer Service URL.
- Audience URI (SP Entity ID): Enter the Entity ID.
- Default RelayState: Enter the Start URL.
- Name ID Format: Select EmailAddress.
- Application Username: Select Email.
- Click Next, and finish creating the app.
Step 2: Assign users to the new app
On the Assignments tab of the app page, you can assign the app to specific users and groups.
On the same page, you can also find Self Service configuration. With that, you can allow users to use Supermetrics with their credentials with or without admin approval, without manual assignments.
Step 3: Share SAML metadata with Supermetrics
On the Sign On tab of the app page, you can find the Metadata URL for SAML 2.0. Please copy the Metadata URL and share it with Supermetrics.
Step 4: Test the integration
After Supermetrics confirms that your metadata file has been received and processed, you can test the integration.
- Have a user access the Supermetrics Hub. The user should be redirected to the Okta sign-in page, where they can authenticate using their Okta Workforce Identity credentials. After successful authentication, the user should be redirected to Supermetrics.
- Once the user is logged in to Supermetrics, verify that the user in the top-right corner of the Supermetrics Hub UI matches their selected Okta Workforce identity.