> Full SurrealDB documentation index: https://surrealdb.com/docs/llms.txt

# Okta

Configure Okta Workforce as an identity provider for single sign-on in SurrealDB. Create an OIDC web app integration in Okta and add an Okta connection in SurrealDB Studio.

Connect Okta to SurrealDB to allow members of your organisation to sign in with their Okta credentials. You create an OpenID Connect app integration in the Okta Admin Console, then enter its details in a new connection in SurrealDB Studio.

Before you start, [verify the email domain](/docs/manage/enterprise/single-sign-on.md#step-1-verify-an-email-domain) your company uses. You also need an Okta account that can create app integrations.

## Step 1: Create an app integration

1. In the Okta Admin Console, open **Applications and Resources**, then **Applications**.
2. Select **Create App Integration**.

![The Applications page in the Okta Admin Console, with the Create App Integration button highlighted.](~/assets/img/surrealdb/manage/enterprise-sso-okta-1.webp)

3. Under **Sign-in method**, select **OIDC - OpenID Connect**.
4. Under **Application type**, select **Web Application**.
5. Select **Next**.

![The Create and deploy private app integrations dialogue in Okta, with OIDC - OpenID Connect and Web Application selected.](~/assets/img/surrealdb/manage/enterprise-sso-okta-2.webp)

## Step 2: Configure the integration

1. Enter an **App integration name**, for example `SurrealDB`.
2. Under **Grant type**, make sure **Authorization Code** is selected.
3. Under **Sign-in redirect URIs**, enter `https://auth.surrealdb.com/login/callback`.
4. Under **Assignments**, choose who can use the integration. You can also assign people or groups later, from the integration's **Assignments** tab.
5. Select **Save**.

![The New Web App Integration form in Okta, with the sign-in redirect URI highlighted.](~/assets/img/surrealdb/manage/enterprise-sso-okta-3.webp)

Only the people and groups assigned to the integration can sign in to SurrealDB through it.

## Step 3: Copy the client credentials

Okta opens the **General** tab of the new integration.

1. Under **Client Credentials**, copy the **Client ID**.
2. Under **Client secrets**, copy the secret. Select the eye icon to show it, or the copy icon beside it.

![The General tab of the SurrealDB app integration in Okta, with the client ID and the client secret highlighted.](~/assets/img/surrealdb/manage/enterprise-sso-okta-4.webp)

You also need your Okta domain, for example `example.okta.com`. It is the domain of your Okta sign-in page, without `-admin`.

## Step 4: Add the connection in SurrealDB

1. Open **Single sign-on** in your enterprise and add a new connection.
2. Select **Okta**.
3. Under **Name the connection**, enter a **Display name**. Members see this name on the sign-in screen.
4. Under **Enter the Okta details**, enter:
    - **Okta domain**: your Okta domain, for example `example.okta.com`.
    - **Client ID**: the client ID from step 3.
    - **Scopes**: optional. Leave it empty to request `openid profile email`.
    - **Client secret**: the client secret from step 3.
5. Under **Route sign-in domains**, select the verified domains to send to this connection. This is optional, and you can change it later.
6. Select **Create connection**.

The **Set up Okta** section of the form shows the redirect URI, with a copy button beside it, if you need it again.

![The New Okta connection form in SurrealDB Studio, with the display name, Okta domain, client ID, client secret and a routed domain filled in.](~/assets/img/surrealdb/manage/enterprise-sso-okta-5.webp)

SurrealDB stores the client secret securely and does not show it again.

## Next steps

If you did not route a domain when you created the connection, [route one now](/docs/manage/enterprise/single-sign-on.md#step-3-route-domains-to-the-connection). Then [choose the applications](/docs/manage/enterprise/single-sign-on.md#step-4-choose-the-applications) that people can sign in to with this connection.
