# Okta

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > OpenID Connect). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/okta
Last updated: 2026-09-25

Learn how to configure Okta as an identity provider for NocoDB.

This article briefs about the steps to configure Okta as Identity service provider for NocoDB

### NocoDB, Retrieve `Redirect URL`

1. Go to `Account Settings`
2. Select `Authentication (SSO)`
3. Click on `New Provider` button
4. On the Popup modal, Specify a `Display name` for the provider; note that, this name will be used to display the provider on the login page
5. Retrieve `Redirect URL`; this information will be required to be configured later with the Identity Provider

<img alt="OIDC SSO Configuration" src={__img0} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img1} placeholder="blur" />
<img alt="OIDC SSO Configuration" src={__img2} placeholder="blur" />

### Okta, Configure NocoDB as an Application

1. Sign in to your [Okta account](https://www.okta.com/) and navigate to the "Get started with Okta" page.
   * Click on `Add App` for the Single Sign-On option.
   * On the `Browse App Integration Catalog` page, select `Create New App`
2. In the pop-up with title `Create a new app integration`
   * Choose `OIDC - OpenID Connect` as the Sign-in method
   * Choose `Web Application` as the Application type
3. Go to `General Settings` on the `New Web App Integration` page
   * Provide your application's name.
   * From the Options in the `Grant type allowed` section, select `Authorization Code` and `Refresh Token`
   * Add the `Redirect URL` under `Sign-in redirect URIs`.
   * From the `Assignments section`, select an option from `Controlled access` to set up the desired accessibility configuration for this application.
   * `Save`
4. On your new application,
   * Go to the `General` tab
   * Copy the `Client ID` and `Client Secret` from the `Client Credentials` section.
5. From `Account` dropdown in navigation bar
   * Copy `Okta Domain`
6. Append "./well-known/openid-configuration" to the `Okta Domain` URL & access it
   * Example: [https://dev-123456.okta.com/.well-known/openid-configuration](https://dev-123456.okta.com/.well-known/openid-configuration)
   * Copy `authorization_endpoint`, `token_endpoint`, `userinfo_endpoint` & `jwks_uri` from the JSON response

### NocoDB, Configure Okta as an Identity Provider

In NocoDB, open `Account Settings` > `Authentication` > `OIDC`. On the "Register OIDC Identity Provider" modal, insert the following information:

* Insert `Client ID` retrieved in step (6) above as `Client ID`
* Insert `Client Secret` retrieved in step (6) above as `Client Secret`
* Insert `authorization_endpoint` retrieved in step (8) above as `Authorization URL`
* Insert `token_endpoint` retrieved in step (8) above as `Token URL`
* Insert `userinfo_endpoint` retrieved in step (8) above as `Userinfo URL`
* Insert `jwks_uri` retrieved in step (8) above as `JWK Set URL`
* Set `Scope` as `openid` `profile` `email` `offline_access`
* In the Username Attribute field, indicate the name of the claim that represents the user's email. The default value is set to "email."

For Sign-in's, user should be able to now see `Sign in with <SSO>` option.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

For information about Okta API Scopes, refer [here](https://developer.okta.com/docs/reference/api/oidc/#scopes)

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* OIDC SSO is available on **NocoDB Cloud** (Business plan and above) and licensed self-hosted deployments (Business plan and above). For access, please reach [**out to sales team**](https://cal.com/nocodb/sales).
* For users on **Business plan**, the SSO configuration menu is available under **Settings** > **Single Sign-On (SSO)** in the workspace sidebar. Refer [here](/docs/product/account-settings/authentication#business-plan) for more details.
* **Domain Verification Required for Cloud Plans**: Before configuring OIDC SSO, you must verify your domain in NocoDB (required for both Business and Enterprise plans in the cloud). Only users with email addresses from verified domains can sign in via SSO. See [Domain Verification](/docs/product/account-settings/authentication#domain-verification) for details.

---

## Related pages

- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/auth0.md): Learn how to configure Auth0 as an identity provider for NocoDB.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/ping-identity.md): Learn how to configure Ping Identity as an identity provider for NocoDB.
- [Azure AD (Entra)](https://nocodb.com/docs/product/account-settings/authentication/oidc-sso/azure-ad.md): Learn how to configure Azure AD as an identity provider for NocoDB.
