Menu
Articles in this section
SSO/SAML: additional providers
Provider-specific SAML and SCIM setup for Okta and OneLogin.
On this page:
Okta
Covers SAML and SCIM setup, so users can be provisioned automatically as well as authenticated. Requires the Enterprise plan and Insightly administrator access. This process works alongside the SAML/SCIM configuration on the Insightly side. See SSO / SAML for that half of the setup.
Insightly Okta Integration Detail Page
Add the integration and configure SAML
- Navigate to the Insightly integration page in Okta and click Add Integration.
- Under General Settings, enter a name for the application and click Next.
- In Insightly, go to System Settings > Security > SAML and SCIM and copy the Sign-in Page URL.
- Back in Okta’s Configure SAML step, paste that URL into the Sign-in page URL field, select Email for Application username format, and click Done.
Okta Advanced Sign-on Settings for Insightly SAML
- On the new app’s Sign-on tab, find the first active certificate under SAML Signing Certificates, open its Actions menu, and select Download Certificate.
SAML Signing Certificate Actions Menu
- Back in Insightly, upload that certificate in the Verification Certificate field on the SAML and SCIM settings page, and click Save.
SAML and SCIM Configuration Settings Page
Configure SCIM
Confirm SCIM is enabled on the Insightly side first (same SAML and SCIM settings page).
- On the Insightly app’s Provisioning tab in Okta, click Configure API Integration.
Insightly Provisioning Tab in Okta Settings
- Check Enable API Integration, and paste the SCIM Token into the API Token field.
Insightly SCIM API Integration Configuration Screen
- Click Test API Credentials to confirm the token works, then Save.
Insightly API Integration Setup Success Screen
- On the Provisioning tab, click Edit, and enable Create Users, Update User Attributes, and Deactivate Users as needed, then Save.
Okta Provisioning to App Settings Panel
- Supported attributes can be reviewed further down the Provisioning to App page. Email and email type are read-only.
Insightly Attribute Mappings in Okta Configuration
- On the Assignments tab, use the Assign dropdown to select Assign to People (or Groups). Assigned users appear in Insightly shortly after. Progress can be tracked in View Logs.
Insightly App Assignments Tab with Assign Dropdown
OneLogin
Covers SAML setup, working alongside the SAML configuration on the Insightly side. See SSO / SAML for that half.
Add a new SAML Custom Connector
- In the OneLogin administration portal, click the Applications dropdown and select Applications.
OneLogin Applications Menu Dropdown Options
- Click Add App, then search for SAML Custom Connector and select SAML Custom Connector (Advanced).
Searching for SAML Custom Connector in OneLogin
- Enter a Display Name and click Save.
Adding a SAML Custom Connector Configuration
Configure SAML
- In the app’s Configuration section, enter the Sign-in page URL from Insightly’s SAML and SCIM settings page into all four fields: Audience (EntityID), Recipient, ACS (Consumer) URL Validator, and ACS (Consumer) URL. Click Save.
SAML Custom Connector Configuration Settings
- In the SSO section, click View Details to see the X.509 certificate.
SAML 2.0 SSO Configuration Settings Panel
- Click Download to save the certificate in X.509 PEM format.
X.509 Certificate Download Interface
- In Insightly, go to System Settings > SAML and SCIM, check Enable SAML Sign-on, click Select File in the Verification Certificate field, choose the downloaded PEM certificate, and click Save.
Insightly SAML SSO and SCIM Settings Panel
You can then sign in to Insightly through the OneLogin portal.
OneLogin Dashboard with Insightly SAML App
Related to