This section outlines how to configure Okta for SAML 2.0 SSO integration with Cleary.
NOTE: There are two environments: sandbox and production.
Sandbox is hosted at pre-gocleary.com and production is hosted at gocleary.com
Each environment will need its own Okta configuration - please send over both.
Step 1 - Create New App in Okta
- Go to Okta dashboard
- Note: These instructions assume you are viewing the “Classic UI”. To set your UI to “Classic”, you can click on Developer Console in the top left of the page to choose "Classic UI".
- Click on Applications in the navigation bar and click on "Applications" in the drop down window.
- Click on the Green "Add Application" button
- Click on "Create New App"
- In the "Create a New Application Integration" popup, choose the following
- Platform: Web
- Sign on method: SAML 2.0
Step 2 - Create SAML Integration
- Under General Settings, enter "Cleary" for app name and click next.
Step 3 - Configure SAML
For sandbox environments
- Single Sign On URL: https://your-cleary-subdomain.pre-gocleary.com/auth/saml/callback
- Check "Use this for Recipient URL and Destination URL"
- Audience URI: https://your-cleary-subdomain.pre-gocleary.com/auth/saml/callback
- Name ID format: EmailAddress
- Application username: Email
For production environments
- Single Sign On URL: https://your-cleary-subdomain.gocleary.com/auth/saml/callback
- Check "Use this for Recipient URL and Destination URL"
- Audience URI: https://your-cleary-subdomain.gocleary.com/auth/saml/callback
- Name ID format: EmailAddress
- Application username: Email
Step 4 - Feedback
- This step can be skipped by clicking “I’m an Okta Customer adding an internal app” and then clicking “Finish”.
After clicking through Step 3, you'll be at the app's page. Click "View Setup Instructions" under "Settings"
Step 5 - Add Credentials to Cleary
- Open the Cleary App
- Navigate to the Admin > App Integrations page
- Expand the Authentication section
- Click the ‘Configure SAML’ button (if you don’t see it, you probably need to disable one of the other authentications types)
- Fill in the fields in the form and click Install
- Additionally, make sure you add the allowed email login domains for your company. People can’t log in if their email domain is not on this list