Configure your SSO provider
Customers on the Enterprise plan may use Okta instead of Google as the SSO provider for their workspace.
Configure Okta SSO
To use Okta with Modelbit you must be on an Enterprise plan. Enabling Okta for your workspace requires the following one-time setup from your Okta administrator:
Begin in Modelbit, in
Settings (click the gear icon in the header), then click the
Okta toggle under
SSO Providers. The first step in the setup wizard will direct you here, to set up a new application for Modelbit at okta.com:
- At okta.com, in the left menu, click
Applications, then click
Applicationsthat appears in the sub-menu.
- Then click
Create App Integration
OIDC - OpenID Connectthen choose
Web Applicationand click
To complete creating the Okta Application, complete the form:
Application Name: Modelbit
Logo: Upload https://doc.modelbit.com/img/modelbit-logo.png
Sign-in redirect URIsfor now. We'll update this value after configuring Modelbit with this Okta application.
Sign-out redirect URIs: https://app.modelbit.com/
Allow everyoneor the limited groups, depending on your IT policies. Click
Proceed to the next step in Modelbit's SSO Wizard and copy
Client Secret and your
Issuer (Okta Domain) from Okta into Modelbit's form. You can copy your Okta Domain from the URL bar of your web browser. Then click
Finally, configure the
Sign-in redirect URI in the Okta application.
- Copy the value from the last step of Modelbit's setup wizard.
General Settingsin the Okta Application
- Paste over the temporary value in
Sign-in redirect URIs
Savein the Okta Application
Your workspace is now configured to authenticate users with Okta!
Testing Okta SSO
To ensure you can rejoin your Modelbit workspace with your new Okta-authenticated user, in
- Ensure the
Automatically add new <your-company>.com userstoggle is enabled, OR
- Invite your Okta user's email to the workspace using the
If you just configured Okta, you're probably logged in with your Google-authenticated user account. Sign out of Modelbit and return to https://app.modelbit.com/
Or sign in with Okta
- Enter your workspace's name, and click
You'll be redirected through Okta and back to Modelbit, and you'll be logged in using your Okta-authenticated account. You can log in with Google or Okta while testing your SSO configuration.
Removing Google SSO
Modelbit supports multiple SSO providers per-workspace. The default SSO provider for every workspace is Google. If you just enabled Okta you may want to disable Google so that only users authenticating through Okta are allowed into the workspace.
In Modelbit's Settings page you can see which users are authenticated with Google vs. Okta. To disable Google as an SSO provider for your workspace:
- Log in to Modelbit with your Okta user by visiting https://app.modelbit.com/ and clicking
Or sign in with Okta.
Settings, and click the toggle next to
Disable Googlein the dialog that appears
Any workspace users currently authenticated with Google will be logged out of the workspace and their email addresses moved to
Pending Invitations. When those users log in with Okta they will automatically rejoin this workspace as Okta-authenticate users.
Please inform your users to log into Modelbit with Okta instead of Google going forward.