One less password for your office team. With Okta, they sign in to NextCrew the same way they sign in to everything else.
Summary
Okta single sign-on (SSO) lets your office team sign in to NextCrew with their Okta account. Add Okta SSO in Settings › App Marketplace, then create a SAML 2.0 app in your Okta Admin Console using the settings below. Once it's on, an Okta option appears on the NextCrew sign-in screen. It's for your office team, not your Crew or clients. What goes wrong: a typo in the sign-on URL or audience URI, so Okta can't hand the sign-in back to NextCrew.
How to do it
- In NextCrew, go to Settings › App Marketplace, find Okta SSO and click Add.
- In your Okta Admin Console, go to Applications › Create App Integration and choose SAML 2.0.
- Name the app, then enter the SAML settings below.
- Click Finish.
- Okta then shows an App Embed Link. Keep it, and follow the instructions Okta gives you after setup. If you're not sure where it goes, contact NextCrew support.
- Sign out and check the Okta option on the NextCrew sign-in screen.
That's single sign-on set up. Read on for the exact Okta settings.
The Okta settings
| Okta setting | Enter |
|---|---|
| App name | Anything your team will recognize, such as NextCrew. |
| App visibility | Leave unticked. |
| Single sign-on URL | https://yourcompany.nextcrew.app/sso/okta |
| Audience URI (SP Entity ID) | https://yourcompany.nextcrew.app |
| Default RelayState | Leave blank. |
| Name ID format | EmailAddress |
| Application username | Okta username |
| Update application username on | Create and update |
| Attribute: FirstName | user.firstName |
| Attribute: LastName | user.lastName |
| Attribute: Tenant | Your agency's own NextCrew tenant number. Each agency has a different one, so ask NextCrew for yours. |
| Group attributes | Leave blank. |
Replace yourcompany with the start of your own NextCrew address.
Why use single sign-on
| Without SSO | With Okta SSO |
|---|---|
| Another password for your team to remember | They sign in with Okta, like everything else. |
| Removing a leaver's access in every system | Turn them off in Okta and they can't sign in. |
If something isn't working
| What you see | Check this |
|---|---|
| No Okta option on the sign-in screen | Okta SSO is added and set up in the App Marketplace. |
| Okta signs in but NextCrew doesn't | The sign-on URL and audience URI match your NextCrew address exactly. |
| The user's name is wrong | The FirstName and LastName attributes are spelled exactly as shown. |
Questions people ask
Who is this for?
Your office team. Crew and clients sign in as usual.
Do I need group attributes?
No. Leave them blank.
Other ways people ask this
- How do I set up SSO?
- Does NextCrew support Okta?
- SAML setup for NextCrew
- Can we sign in with Okta?
Related guides
- App Marketplace: Start Here — the other apps
- Users and Permissions: Start Here — your office users
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article