Sign In with Okta (SSO)

Modified on Wed, 30 Sep at 11:37 PM

One less password for your office team. With Okta, they sign in to NextCrew the same way they sign in to everything else.

Summary

Okta single sign-on (SSO) lets your office team sign in to NextCrew with their Okta account. Add Okta SSO in Settings › App Marketplace, then create a SAML 2.0 app in your Okta Admin Console using the settings below. Once it's on, an Okta option appears on the NextCrew sign-in screen. It's for your office team, not your Crew or clients. What goes wrong: a typo in the sign-on URL or audience URI, so Okta can't hand the sign-in back to NextCrew.

How to do it

  1. In NextCrew, go to Settings › App Marketplace, find Okta SSO and click Add.
  2. In your Okta Admin Console, go to Applications › Create App Integration and choose SAML 2.0.
  3. Name the app, then enter the SAML settings below.
  4. Click Finish.
  5. Okta then shows an App Embed Link. Keep it, and follow the instructions Okta gives you after setup. If you're not sure where it goes, contact NextCrew support.
  6. Sign out and check the Okta option on the NextCrew sign-in screen.

That's single sign-on set up. Read on for the exact Okta settings.


The Okta settings

Okta settingEnter
App nameAnything your team will recognize, such as NextCrew.
App visibilityLeave unticked.
Single sign-on URLhttps://yourcompany.nextcrew.app/sso/okta
Audience URI (SP Entity ID)https://yourcompany.nextcrew.app
Default RelayStateLeave blank.
Name ID formatEmailAddress
Application usernameOkta username
Update application username onCreate and update
Attribute: FirstNameuser.firstName
Attribute: LastNameuser.lastName
Attribute: TenantYour agency's own NextCrew tenant number. Each agency has a different one, so ask NextCrew for yours.
Group attributesLeave blank.

Replace yourcompany with the start of your own NextCrew address.


Why use single sign-on

Without SSOWith Okta SSO
Another password for your team to rememberThey sign in with Okta, like everything else.
Removing a leaver's access in every systemTurn them off in Okta and they can't sign in.

If something isn't working

What you seeCheck this
No Okta option on the sign-in screenOkta SSO is added and set up in the App Marketplace.
Okta signs in but NextCrew doesn'tThe sign-on URL and audience URI match your NextCrew address exactly.
The user's name is wrongThe FirstName and LastName attributes are spelled exactly as shown.

Questions people ask

Who is this for?

Your office team. Crew and clients sign in as usual.

Do I need group attributes?

No. Leave them blank.


Other ways people ask this

  • How do I set up SSO?
  • Does NextCrew support Okta?
  • SAML setup for NextCrew
  • Can we sign in with Okta?

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article