> ## Documentation Index
> Fetch the complete documentation index at: https://brightdata-ipv6-release.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# How to set up SSO with Okta in Bright Data?

**Requirements**

* An Okta organization account with admin permission
* A Bright Data account with admin permission

**Steps:**

1. On your Okta admin dashboard, choose '**Applications > Applications**'

```sh theme={null}
https://[your_domain]-admin.okta.com/admin/apps/active
```

2. Click '**Create App Integration**'

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_1.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=1e6f80e2ec078f870882f186f10faf51" alt="mceclip0.png" width="612" height="234" data-path="images/general/authentication/okta_1.png" />

3. Select '**OIDC - OpenID Connect**' as the Sign-in method,

4. Select'**Web Application**' as the Application type and click '**Next**'

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_2.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=5b650a5d46df5df4f4f9dc6ead0e5d5f" alt="mceclip1.png" width="853" height="739" data-path="images/general/authentication/okta_2.png" />

5. At this point you should be redirected to a new web app integration page. Here you can name your app integration (we recommend to use "**Bright Data Control Panel**" name).

6. At ‘Grant type’ select **Implicit** along with **Authorization Code**

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_3.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=35b0e127a65a81957d153ecb8ab48c03" alt="mceclip0.png" width="932" height="554" data-path="images/general/authentication/okta_3.png" />

7. Go to Bright Data [Control Panel](https://brightdata.com/cp/setting)

8. Open OKTA configuration dialog

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_4.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=9ba62b6e6f4aa6d1cdb516caf5f04da8" alt="mceclip1.png" width="460" height="420" data-path="images/general/authentication/okta_4.png" />

9. Copy **"Sign-in redirect URI"**

**<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_5.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=21b9c8395d4566dc711cfc2503f02b45" alt="mceclip2.png" width="630" height="630" data-path="images/general/authentication/okta_5.png" />**

10. Paste it to according field in New App setup in OKTA

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_6.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=8f244ead5be2aed2adcc093bad6abd42" alt="mceclip3.png" width="964" height="625" data-path="images/general/authentication/okta_6.png" />

11. Repeat the same for **"Sign-out URI"**

12. At ‘Assignments’, select an access level as you want

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_7.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=6817899169773dc92e19284b7f9fdde3" alt="mceclip6.png" width="894" height="291" data-path="images/general/authentication/okta_7.png" />

13. Click '**Save**'

14. Now, you should land on your new app integration settings page.

Copy your **Client ID**, **Client Secret**, and **Okta domain** to OKTA setup dialog in your Bright Data Control Panel. 

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_8.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=1c1502c7b68301fde15bf02d8879d5f2" alt="mceclip4.png" width="769" height="582" data-path="images/general/authentication/okta_8.png" />

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_9.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=20e6a20eeb2e5d4751c4ce1b776b58c3" alt="mceclip5.png" width="613" height="630" data-path="images/general/authentication/okta_9.png" />

15. Click **"Activate"**.

Skip step 16 if you selected "Allow everyone to access"

16. Go to **"Assignments"** tab and assign users allowed to use this integration

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_10.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=1c23abba27c5a05c6841d4fc3819ab5d" alt="mceclip6.png" width="767" height="721" data-path="images/general/authentication/okta_10.png" />

17. Go to Bright Data Settings page and make sure all required users presented.

We're working on users provisioning support, at the moment - you should manage it manually.

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_11.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=c312542a1ab55ef8a4aa077655be737e" alt="mceclip7.png" width="829" height="547" data-path="images/general/authentication/okta_11.png" />

***The following steps are optional. They are for enabling your users to launch authentication from their dashboard or the Okta Chrome extension.***

18. Scroll down to ‘General Settings’ and click **Edit**

19. Set these settings:

* Login initiated by: **Either Okta or App**
* Application visibility: **Display application icon to users**
* Login flow: **Redirect to app to initiate login (OIDC Compliant)**
* Copy Initiate login URI from Control Panel

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_12.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=cfb0df6b1d876e415f4d459267947387" alt="mceclip8.png" width="619" height="632" data-path="images/general/authentication/okta_12.png" />

<img src="https://mintcdn.com/brightdata-ipv6-release/goTKF0pTvyg90BEz/images/general/authentication/okta_13.png?fit=max&auto=format&n=goTKF0pTvyg90BEz&q=85&s=9ce0dd3b269f3e9733be9b4690bffd02" alt="mceclip9.png" width="771" height="609" data-path="images/general/authentication/okta_13.png" />

20. Save changes. **Now the integration is ready to work.**

**Notes**

* Okta Domain should be the one that appears in your app integration settings (**yourcompany.okta.com**), NOT the one you are seeing as an admin (yourcompany-admin.okta.com)

* Make sure the **Credentials** provided to Bright Data are correct, we cannot check them on our side.

-  **Sign-in Redirect URI** is a must in order to make the SSO feature work correctly\
-  **Initiate login URI** is needed if the you wants to be able to use the feature from the Okta Chrome extension or the Okta dashboard
