Integrations: Okta

How to Configure SAML 2.0 for Klnch People Platform

Prerequisites

An existing account in Klnch People Platform and a user with admin access.

Supported Features

The Okta/Klnch People Platform SAML integration currently supports the following features:
ID-initiated SSO
JIT (Just-In-Time) Provisioning
For more information on the listed features, visit the Okta Glossary.

Configuration

Please reach to support@klnch.com to configure the account.

SAML configuration

You will need to provide three configuration values from the 'Klnch People Platform' app:

Go to the 'Sign On' tab > SAML 2.0.
Expand 'More Details' and copy these two values:
Issuer
Signing Certificate
Expand 'Certificate fingerprint' and copy the third value
SHA1 (formatted)

SCIM configuration
Select the SCIM version 2.0
Use Klnch's SCIM base URL at your Okta config page
Enter email as the Unique identifier field for users
Supported provisioning actions:
Push New Users
Push Profile Updates
Select the Authentication Mode as HTTP Header
Enter the SCIM auth token from your Okta config page
In the Provisioning >> To App Enable:
Create Users
Update User Attributes
Deactivate Users