Llim.run

Single sign-on with Okta

The Okta app integration already contains the Limrun redirect and logout settings, so you install the app, verify your email domain, copy the Okta connection values into Limrun, and test sign-in. For other identity providers, see Single sign-on.

Before you start

You need:

Supported features

Limrun supports:

For Universal Logout, open the application settings in Okta and enable App logs out when Okta system or admin initiates logout.

Verify your domain in Limrun

Each SSO domain must be verified before users with that domain can sign in through the OIDC connection. Verification needs access to your DNS records; if that is not possible, contact Limrun support for manual verification.

  1. Open console.limrun.com.

  2. Go to Settings.

  3. In Domain Verification, add the email domain that should use Okta SSO.

  4. Create the TXT record shown in the verification dialog:

    DNS fieldValue
    TypeTXT
    Host / NameCopy from Limrun.
    ValueCopy from Limrun.
  5. After the DNS record is published, click Verify DNS in Limrun.

Add Limrun in Okta

  1. In the Okta Admin Console, go to Applications > Browse App Catalog.
  2. Search for Limrun.
  3. Add the Limrun app integration from the catalog.
  4. Assign the users or groups that should be able to sign in to Limrun.

Copy the connection values from Okta

Open the Limrun app integration in Okta and go to the Sign On tab. Copy these values:

Limrun fieldOkta value
Client IDThe app's client ID.
Client SecretThe app's client secret.
Issuer URLThe issuer from Okta's OpenID Provider Metadata.

To find the issuer, open the OpenID Provider Metadata link in Okta and copy the issuer value from the JSON document.

For most Okta orgs, the issuer looks like:

https://your-org.okta.com

Save the Okta connection in Limrun

  1. In Limrun, go to Settings > Single Sign-On.
  2. Enter the Issuer URL, Client ID, and Client Secret from Okta.
  3. Click Save.

Sign in with Okta

Users can start from Limrun:

  1. Go to console.limrun.com/authn/login.
  2. Click Continue with SSO.
  3. Enter your work email address.
  4. Complete authentication in Okta.

Users can also start from the Limrun app tile in Okta.

Troubleshooting

Users see "SSO not configured". Confirm the user's email domain is added under Settings > Domain Verification and shows Verified.

Okta says the client cannot use a custom authorization server. Use the Okta org issuer, for example https://your-org.okta.com, instead of https://your-org.okta.com/oauth2/default.

A user authenticates in Okta but cannot enter Limrun. Confirm the user's email domain is verified in Limrun and assigned to the same organization as the OIDC connection.

What the Okta app configures