Single sign-on with Okta
The Okta app integration already contains the Limrun redirect and logout settings, so you install the app, verify your email domain, copy the Okta connection values into Limrun, and test sign-in. For other identity providers, see Single sign-on.
Before you start
You need:
- Admin access to your Okta org.
- Admin access to the Limrun organization.
- Access to the DNS provider for the email domain your users sign in with.
Supported features
Limrun supports:
- SP-initiated SSO
- IdP-initiated SSO
- Just-In-Time provisioning
- Single Logout
- Universal Logout through Global Token Revocation
For Universal Logout, open the application settings in Okta and enable App logs out when Okta system or admin initiates logout.
Verify your domain in Limrun
Each SSO domain must be verified before users with that domain can sign in through the OIDC connection. Verification needs access to your DNS records; if that is not possible, contact Limrun support for manual verification.
-
Open console.limrun.com.
-
Go to Settings.
-
In Domain Verification, add the email domain that should use Okta SSO.
-
Create the TXT record shown in the verification dialog:
DNS field Value Type TXTHost / Name Copy from Limrun. Value Copy from Limrun. -
After the DNS record is published, click Verify DNS in Limrun.
Add Limrun in Okta
- In the Okta Admin Console, go to Applications > Browse App Catalog.
- Search for
Limrun. - Add the Limrun app integration from the catalog.
- Assign the users or groups that should be able to sign in to Limrun.
Copy the connection values from Okta
Open the Limrun app integration in Okta and go to the Sign On tab. Copy these values:
| Limrun field | Okta value |
|---|---|
| Client ID | The app's client ID. |
| Client Secret | The app's client secret. |
| Issuer URL | The issuer from Okta's OpenID Provider Metadata. |
To find the issuer, open the OpenID Provider Metadata link in Okta and copy the issuer value from the JSON document.
For most Okta orgs, the issuer looks like:
https://your-org.okta.comSave the Okta connection in Limrun
- In Limrun, go to Settings > Single Sign-On.
- Enter the Issuer URL, Client ID, and Client Secret from Okta.
- Click Save.
Sign in with Okta
Users can start from Limrun:
- Go to console.limrun.com/authn/login.
- Click Continue with SSO.
- Enter your work email address.
- Complete authentication in Okta.
Users can also start from the Limrun app tile in Okta.
Troubleshooting
Users see "SSO not configured". Confirm the user's email domain is added under Settings > Domain Verification and shows Verified.
Okta says the client cannot use a custom authorization server. Use the Okta org issuer, for example https://your-org.okta.com, instead of https://your-org.okta.com/oauth2/default.
A user authenticates in Okta but cannot enter Limrun. Confirm the user's email domain is verified in Limrun and assigned to the same organization as the OIDC connection.
What the Okta app configures
- The Limrun Okta app configures the redirect URI, initiate login URI, logout redirect URI, and Universal Logout endpoint.
- A Limrun organization has one OIDC connection.
- Without SCIM, a first Okta sign-in creates an account and joins the organization. With SCIM provisioning, provisioning creates the account before sign-in. New users can sign in after activation when they are active in the directory and belong to a group mapped to a Limrun role.
Was this guide helpful?