<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Send a Custom RelayState to an Application Through an IdP-Initiated Authentication URL in Okta

Single Sign-On
Okta Classic Engine

Overview

Handling Identity Provider (IdP)-initiated authentication passing through a RelayState requires using the Sign on URL in Okta. The RelayState parameter maintains state information between the IdP and the application during the Security Assertion Markup Language (SAML) Single Sign-On (SSO) process. Include the RelayState parameter in the SSO URL to successfully send a custom RelayState to an application.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Org2Org Integrations

Solution

What steps configure a custom RelayState for an application through an IdP-initiated authentication URL?

Navigate to the application settings in the Okta Admin Console to locate the Sign on URL and format the Org2Org URL to include the custom RelayState parameter.

  1. In the Okta Admin Console, navigate to the application settings page for the Hub/Spoke configuration.
  2. Under the Sign on tab, locate the More details section and use the Sign on URL to handle IdP-initiated authentication passing through a RelayState.
    NOTE: See step 4C in the section Configuring an Application for Hub/Spoke for more information.
  3. Format the Org2Org URL with a RelayState using the following structure:

https://<SubdomainName>.okta.com/app/okta_org2org/<AppKey>/sso/saml?RelayState=https://<SubdomainNameOfHub>.okta.com/app/<APPName>/<AppKey>/sso/saml%3FRelayState%3D<CustomRelayState>

 

    • "https://<SubdomainName>.okta.com/app/okta_org2org/<AppKey>/sso/saml" represents the Sign on URL of the Org2Org application from the Spoke.
    • "https://<SubdomainNameOfHub>.okta.com/app/<APPName>/<AppKey>/sso/saml" represents the Sign on URL of the application from the Hub.
    • "%3FRelayState%3D<CustomRelayState>" represents the encoded version of "?RelayState=<CustomRelayState>".
    • "<CustomRelayState>" represents any valid URL, such as "https://google.com".

 

Use the newly created URL in a bookmark application. After authenticating into the Hub and the application, users accessing the URL land on the <CustomRelayState>.

Loading
Send a Custom RelayState to an Application Through an IdP-Initiated Authentication URL in Okta | Okta Support