<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009M93ptCABOkta Classic EngineIntegrationsAnswered2025-09-13T09:01:51.000Z2023-06-21T15:48:43.000Z2023-07-13T09:31:56.000Z

0kp09 (0kp09) asked a question.

I have JIRA and Okta integrated. If I log into okta first , I don't need to log into JIRA. But if I log into JIRA , I'm redirected to log into okta

Hello,

 

I have integrated JIRA and Okta. When I log into Okta first, I am automatically logged into JIRA without having to enter my credentials again. However, if I log into JIRA first, I am redirected to log into Okta again. I would like to eliminate the need for this second login.

 

Thank you,

Marcela


  • DonF.81354 (Customer)

    Hi! Great question. What I beleive you are referring to is the user experience difference between IdP initiated vs. Service Provider (SP) initiated.

     

    In the example above, the Service Provider would be JIRA and the IdP is Okta. If navigating from Okta to JIRA is a single login beginning with Okta, this is the typical IdP initiated user experience. The login session is transferred to JIRA as a pre-existing trust relationship has been configured between the two.

     

    Service Provider login will re-direct users back to Okta for authentication once they supply their username, as the domain will help JIRA identify the appropriate Okta org to re-direct the request to. Once re-directed, the user will need to login, where (if successful) they will be re-directed back to JIRA.

     

    This second user experience is what is expected on how users would authenticate to JIRA, using Okta, when navigating to JIRA first. If they are in a browser session in which they are already authenticated, then I would probably expect this re-direct would not be needed. But if opening up an incognito window or something similar, you would need to authenticate again.

     

    Please let me know if you have any further questions or concerns - thanks!

    Expand Post
    Selected as Best
  • DonF.81354 (Customer)

    Hi! Great question. What I beleive you are referring to is the user experience difference between IdP initiated vs. Service Provider (SP) initiated.

     

    In the example above, the Service Provider would be JIRA and the IdP is Okta. If navigating from Okta to JIRA is a single login beginning with Okta, this is the typical IdP initiated user experience. The login session is transferred to JIRA as a pre-existing trust relationship has been configured between the two.

     

    Service Provider login will re-direct users back to Okta for authentication once they supply their username, as the domain will help JIRA identify the appropriate Okta org to re-direct the request to. Once re-directed, the user will need to login, where (if successful) they will be re-directed back to JIRA.

     

    This second user experience is what is expected on how users would authenticate to JIRA, using Okta, when navigating to JIRA first. If they are in a browser session in which they are already authenticated, then I would probably expect this re-direct would not be needed. But if opening up an incognito window or something similar, you would need to authenticate again.

     

    Please let me know if you have any further questions or concerns - thanks!

    Expand Post
    Selected as Best
  • 0kp09 (0kp09)

    Hello there! Thank you for your response. I have another question related to this topic. If I am already logged into Okta and I click on a JIRA ticket link in an email, it opens in a new tab in the same browser. However, I am prompted to log into JIRA even though I am already logged into Okta. Is it necessary/mandatory to open JIRA within the Okta dashboard first or is there a configuration that can be adjusted to prevent this?

     

    Thank you.

     

     

    Expand Post
  • DonF.81354 (Customer)

    From what I understand, and I could be wrong, but this is going to be dictated by the length of your session. For instance, if you just log in and then click the link, does it do the same? I have this behavior occasionally when using ServiceNow or some equivalent and as long as I am still logged on in an active session, re-authentication is not needed. Otherwise, this may be a setting in JIRA that I am unaware of. This is typically all dictated by the session cookie that is in your browser.

     

    Finally, Be sure to check your sign-on policy as well for any setting that might shorten your session lifetime too much

     

    Configure an Okta Sign-On Policy

     

     

    Expand Post
  • a0n5s (a0n5s)

    @0kp09 (0kp09) As @DonF.81354 (Customer) told, when the JIRA session is timeout or not have activate JIRA session,it will rediret to Okta. you can set JIRA as both Okta and APP in Okta App setting. use can click JIRA icon in Okta to login JIRA.

This question is closed.
Loading
I have JIRA and Okta integrated. If I log into okta first , I don't need to log into JIRA. But if I log into JIRA , I'm redirected to log into okta