How to Connect Salesforce With Okta Using OpenID Connect
Last Updated:
Overview
Administrators can connect Salesforce with Okta using OpenID Connect (OIDC) to enable Single Sign-On (SSO) for users. Configuring Okta as an OIDC Identity Provider (IdP) and configuring the authentication provider details in Salesforce establishes this connection.
Applies To
- Okta Classic Engine
- Okta Identity Engine (OIE)
- Salesforce
- OpenID Connect
Solution
What are the prerequisites for the Salesforce integration?
Review the Salesforce environment to ensure it meets the necessary edition and permission requirements before configuring the integration.
- Verify the Salesforce tenant has an Enterprise, Performance, Unlimited, or Developer edition.
- Ensure the Salesforce account has permissions to view Setup and Configuration.
- Ensure the Salesforce account has permissions to edit Customize Applications and Manage Auth. Providers.
Configure Okta as an OpenID Connect Identity Provider
Create the OpenID Connect application in the Okta Admin Console and gather the client credentials required for the Salesforce authentication provider.
- Navigate to the Okta Admin Console.
- Go to Applications > Applications and select Add Application, then Create New App.
- Select Web for the Platform and OpenID Connect for the Sign on method.
- Enter Salesforce OpenID Connect SSO in the Name field.
- Enter
http://placeholderin the Sign-in redirect URIs field. - Click Save.
- Navigate to the Assignments tab and assign the application to the appropriate users or groups.
- Navigate to the General tab, scroll to the Client Credentials section, and copy the Client ID and Client Secret.
What steps configure the authentication provider in Salesforce?
Configure the authentication provider in Salesforce using the Okta client credentials and endpoint URLs to establish the connection.
- Log in to the Salesforce administrator interface.
- Navigate to Identity > Auth. Provider and select New.
- Select Open ID Connect for the Provider Type.
- Enter Okta in the Name and URL Suffix fields.
- Paste the copied Client ID into the Consumer Key field.
- Paste the copied Client Secret into the Consumer Secret field.
- Enter
https://<oktaorg>.okta.com/oauth2/v1/authorizein the Authorize Endpoint URL field, replacing<oktaorg>.okta.comwith the Okta organization URL (for example,<company>.okta.com). - Enter
https://<oktaorg>.okta.com/oauth2/v1/tokenin the Token Endpoint URL field. - Enter
https://<oktaorg>.okta.com/oauth2/v1/userinfoin the User Info Endpoint URL field. - Enter openid in the Default scopes field.
- Select the Send access token in header checkbox.
- Clear the Send client credentials in header checkbox.
- Configure the Registration Handler and Execute Registration As fields to manage Just-In-Time (JIT) user creation.
- Click Save.
- Copy the Callback URL and OAuth-Only Initialization URL from the Salesforce Configuration page.
Finalize the Okta Application Configuration
Update the Okta application with the Salesforce callback URL and test the initialization to complete the integration.
- In the Okta Admin Console, navigate to Applications > Applications and select the Salesforce OpenID Connect SSO application.
- Navigate to the General tab and click Edit in the General Settings section.
- Paste the copied Callback URL into the Login redirect URIs field.
- Click Save.
- Sign out of Salesforce and access the copied OAuth-Only Initialization URL to verify the configuration.
