<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Understanding Non-Standard IdP Issuer URIs in Okta CIAM

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

This Knowledge Article delves into the intricacies of the IdP Issuer URI, specifically in non-standard scenarios. One such instance arises during the integration of Okta with a customer's Identity Providers (IDPs) via SAML, where a non-standard URI (i.e., not a URL) was used as the Issuer URI. Despite the seemingly incorrect format, the SSO login for the customer's users operates without issue.
 

Applies To

  • Okta Admins integrating Okta with external IDPs via SAML, specifically using non-standard IdP Issuer URIs.

Cause

The issue arises from the integration of Okta with IDPs using a non-standard URI as the Issuer. This can lead to questions and doubts regarding its validity and the integration process.
 

Solution

Even though a non-standard IdP Issuer URI (i.e., not a URL) might not adhere to a conventional URI format, it is still valid and functional within the SAML integration. Through extensive trials, it is confirmed that the SSO login process works seamlessly with such URIs. This is attributed to the fact that the system's requirements focus more on the acceptance of the value by the application rather than the strict adherence to traditional URI structures.
 

Consequently, during the integration process, as long as the value in the Issuer URI is accepted by the application, the SSO login functionality will remain unaffected. However, it is prudent to approach any non-standard configuration with caution. Always confirm the correct functionality with a test user and the relevant parties before deploying it to the entire user base.
 

NOTE: Even though non-standard URI values can function effectively in some cases, validating them for correctness helps maintain system integrity and reduces the potential for complications in the future.

Loading
Okta Support - Understanding Non-Standard IdP Issuer URIs in Okta CIAM