> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Okta

> Import employees and groups from Okta over SCIM and set up single sign-on, step by step, using the Cimento AI app from the Okta Integration Network.

Okta sends Cimento the people and groups you assign to the Cimento AI app and keeps them up to date over SCIM. The same app sets up SAML single sign-on, so assigned employees sign in to Cimento through Okta.

## Before you start

* An Okta Super Administrator or Application Administrator, to add the app and configure provisioning.
* A Cimento user with the Admin role, to reveal the API token in step 4. Integrations admins can do every other step.
* Your organization's email domains registered with Cimento. Single sign-on only covers those domains, so ask your Cimento contact to add any that are missing.

<Note>
  Your organization connects one directory, and switching to another later needs Cimento support. As soon as you click **Begin Setup**, employees come from Okta: you can no longer add or upload employees in Cimento, or edit their names, email addresses, status or departments.
</Note>

## Steps

<Steps>
  <Step title="Start setup in Cimento">
    Go to **Admin → Integrations → Employee data**. Under **Directory provider**, choose Okta and click **Begin Setup**. The setup guide opens at **Add Application**.
  </Step>

  <Step title="Add the Cimento AI app in Okta">
    Click **Open Okta Integration Network** to open the Cimento AI app. Signed in as an Okta admin, click **Add Integration** and follow the prompts. On the app's **Assignments** tab, assign the people and groups who should be in Cimento. Back in Cimento, click **Next**.
  </Step>

  <Step title="Connect single sign-on">
    In the Okta Admin Console, open **Applications**, select **Cimento AI** and open the **Sign On** tab. Copy the **Metadata URL** from the SAML section. Paste it into the **Metadata URL** step in Cimento and click **Save configuration**. When Cimento shows **SSO configured**, people who sign in to Cimento with an address in your domains are sent to Okta.
  </Step>

  <Step title="Turn on provisioning">
    In Okta, open the app's **Provisioning** tab, click **Configure API Integration** and check **Enable API integration**. In Cimento's **Provisioning** step, click **Copy** next to **API Token** and paste it into Okta's **API Token** field. If Okta also shows a **Base URL** field, copy that value from Cimento as well. Click **Test API Credentials**, then **Save**.
  </Step>

  <Step title="Choose what Okta sends">
    Under **Provisioning › To App**, click **Edit**, enable **Create Users**, **Update User Attributes** and **Deactivate Users**, and save. To send groups, open the **Push Groups** tab and push the groups you want in Cimento. Assigning a group only provisions its members; pushing it creates the group in Cimento.
  </Step>

  <Step title="Verify">
    In Cimento's **Verify** step, click **Test connection**. It checks that single sign-on is live and activates the integration. Okta's **Test API Credentials** in step 4 is the check for provisioning.
  </Step>
</Steps>

## If something goes wrong

| Cimento shows | What to do |
| - | - |
| Single sign-on could not be set up from that URL | Check that you copied the **Metadata URL** from the **Sign On** tab, then save it again. |
| Your organization has no email domains set up yet | Ask your Cimento contact to add your email domains, then save the metadata URL again. |
| Single sign-on for your organization's domains is already connected with a different metadata URL | Contact Cimento support to change it. |
| Single sign-on is not connected for your organization yet | Go back to the **Metadata URL** step and save it again. |
| You don't have permission to view this value | Ask a Cimento user with the Admin role to copy the API token for you. |

## What Okta sends

Cimento uses each employee's primary email, name, title, department, manager and phone numbers, and mirrors the groups you push. See [What Okta and Microsoft Entra ID send](/getting-started/employee-directory#what-okta-and-microsoft-entra-id-send) for how each attribute maps and what happens when someone leaves.

## Stop provisioning

The API token lets Okta create, update and deactivate employees in Cimento, so store it like a password. To stop Okta from updating Cimento, uncheck **Enable API integration** on the app's **Provisioning** tab, or remove the Cimento AI app from Okta.
