For the complete documentation index, see llms.txt. This page is also available as Markdown.

Setup Okta SSO

This integration enables authentication via OpenID Connect (OIDC) and automated user provisioning through System for Cross-domain Identity Management (SCIM).

Required role to configure: Admin or higher.

Users with lower roles can view this feature but cannot change its configuration.


Overview

Seemore integrates with Okta using:

  • OIDC (OpenID Connect) — user authentication

  • SCIM (System for Cross-domain Identity Management) — automated user and role provisioning

This setup allows Okta administrators to:

  • Manage Seemore users directly in Okta

  • Assign and sync roles (owner, admin, editor, viewer)

  • Map Okta groups to Seemore roles and sync them automatically

  • Automatically create or deactivate users


Prerequisites

Before you start:

  • Ensure you have Admin rights in both Okta and Seemore.

  • Obtain from Seemore:

    • SCIM base URL

    • Bearer token (from Integrations → SCIM Tokens)

  • Ensure each Okta user has a unique External ID for matching.

  • Enable SCIM provisioning in your Seemore tenant.

Seemore now supports Okta group synchronization. Push your Okta groups to Seemore and assign one or more Seemore roles to each group — members receive those roles automatically on their next login. See Step 6 and Step 7 below.


Setup Steps

Step 1 — Create the Seemore App in Okta

  1. In the Okta Admin Console, go to Applications → Applications → Create App Integration.

  2. Select:

    • Sign-in method: OIDC – OpenID Connect

    • Application type: Web Application

  3. Configure:

    • App name: Seemore

    • Login redirect URI:

  4. Assign test users or groups to the app.


Step 2 — Configure OIDC in Seemore

  1. In Seemore, open Settings → Preferences → Authentication → Okta.

  2. Enter:

    • Okta domain (from Okta)

    • Client ID / Secret (from the Okta app)

  3. Save and test. You should be redirected to Okta for sign-in and back to Seemore upon success.


Step 3 — Enable SCIM Provisioning in Seemore

  1. Check the box to Enable SCIM Provisioning and save.

  2. Click Create Token, then Save the generated token. You won’t be able to view it again later.


Step 4 — Enable SCIM Provisioning in Okta

  1. Confirm that an OpenID Connect application has already been registered in the Okta Workforce tenant for OIDC-based authentication.

  2. Confirm that your OpenID Connect application has disabled Federation Broker Mode.

  3. Register a second application in Okta:

    • Go to Applications → Applications → Create App Integration

    • Choose Secure Web Authentication, then Next

  4. On the General App Settings page:

    • Set a name and a URL

    • Select Do not display application icon to users

    • The URL entered is not used in the SCIM integration

  5. Select Finish.

  6. Navigate to the General tab → EditProvisioning section.

  7. Choose SCIM, then Save.

  8. Navigate to Provisioning → Integration → Edit, and configure the following:

    • SCIM connector base URL: SCIM Endpoint URL copied earlier

    • Unique identifier field for users: userName

    • Under Supported provisioning actions, enable:

      • Push New Users

      • Push Profile Updates

    • Authentication Mode: HTTP Header

    • Paste the token value into the Authorization field

    • (Optional) Test the connection, then choose Save.

  9. Go to Provisioning → Settings → To App → Edit, then:

    • Enable Create Users, Update User Attributes, and Deactivate Users

    • Choose Save.

  10. Under Attribute Mappings, se the X button to delete the following lines, which are not needed and may cause issues during PUT operations:

    Attribute
    Value

    Primary email type

    (user.email != null && user.email != '') ? 'work' : ‘'

    Primary phone type

    (user.primaryPhone != null && user.primaryPhone != '') ? 'work' : ‘'

    Address type

    (user.streetAddress != null && user.streetAddress != '') ? 'work' : ‘'

    Use the Attribute Mappings section to configure any additional SCIM attributes you want Okta WIC to send to your SCIM endpoint. If you add custom attributes, they must include a valid SCIM 2.0 external namespace property. For more information on external namespaces, read Okta's help section.

You can now test user provisioning in the Assignments tab or test update operations by editing user attributes under Directory → People in Okta.


Step 5 — Map User Attributes

Go to Provisioning → To App → Mappings and configure the below fields:

Add a custom property named externalId to link Okta users with Seemore users.

Property
Value

External name

externalId

External namespace

urn:ietf:params:scim:schemas:core:2.0:User

Data type

string

Okta Attribute
Seemore Attribute
Description

user.getInternalProperty("id")

user:external_id

Correlation ID between Okta and Seemore

user.email

user:email

Primary email address


Step 6 — Push Okta groups to Seemore

Seemore can assign roles based on the Okta groups a user belongs to. First, tell Okta which groups to send:

  1. In the Okta Seemore (SCIM) application, open the Push Groups tab.

  2. Choose Push Groups → Find groups by name (or by rule) and add the groups whose members should receive Seemore roles.

  3. Save. Okta pushes the selected group definitions — and their memberships — to Seemore.

Only the groups you explicitly push appear in Seemore. After the first push, Okta keeps membership in sync automatically; changes take effect on each user's next login.

Step 7 — Assign Seemore roles to your groups

Once your groups are pushed, map each one to the Seemore roles its members should receive.

  1. In Seemore, open Settings → Preferences → Authentication → Okta and make sure Enable SCIM Provisioning is on.

  2. Find the Group → role assignment section. The groups you pushed from Okta appear here. If a group is missing, confirm it is selected under Push Groups in Okta, then refresh the page.

  3. For each group, select one or more roles: owner, admin, editor, or viewer.

  4. Click Save roles.

How role resolution works

  • A user receives the combined roles of every group they belong to.

  • Roles are applied on the user's next login — assign or change them before the user signs in again.

  • Group membership is authoritative: on each login, a user's owner/admin/editor/viewer roles are reconciled to match the roles their groups grant. Removing a role from a group — or removing the user from the group — revokes that role on the user's next login.

Alternative: send roles as a per-user SCIM attribute

Instead of mapping groups, you can send Seemore roles directly on each user as a multi-value SCIM attribute named roles.

In Okta:

  1. Edit the Seemore app’s schema by adding a custom attribute:

    • Name: roles

    • External name: user:roles

    • Type: Array

  2. Map the Okta role or group to this attribute:

    • Okta source: user.role (or your internal role field)

    • Target: roles

  3. Allowed values:

    • owner

    • admin

    • editor

    • viewer

⚙️ Technical Note: The SCIM spec requires this field to be an array (e.g., [{type:"XXX", value: "admin"}]), not a single string.

Step 8 — Provision and Test

  1. Assign a test user in Okta to the Seemore app and to at least one pushed group.

  2. Verify in Seemore:

    • User appears under Admin → Users

    • External ID and email are correct

    • Role will sync upon user’s first login (session-level role binding)


Troubleshooting

Symptom
Cause
Resolution

User not created

Invalid SCIM credentials

Check API token and Base URL

Duplicate users

external_id mismatch

Ensure user:external_id is unique

Roles missing

Sent as string

Change to array type

Role not visible post-provision

Role applies at session level

User must re-login

Group not listed in Seemore

Group not pushed from Okta

Add the group under Push Groups in Okta, then refresh the settings page

Group roles not applied

User has not logged in since the change

Group roles apply on the next login — have the user sign in again


Validation Checklist

✅ SCIM connection tested successfully ✅ User created in Seemore after Okta push ✅ Pushed Okta groups appear in the Group → role assignment section ✅ Each group is mapped to the intended Seemore role(s) ✅ Role appears correctly after login ✅ External ID matches Seemore internal ID


Last updated