> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.toggl.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Setting up SSO for Okta

If you are setting up SSO for Okta, these instructions will be useful for you!

1. Log in to the Okta Admin panel and choose **Create App Integration** in the **Applications** tab
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-1-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-1-1.jpg)
2. A pop-up will appear, choose **SAML 2.0** and click **Next**
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-2a-3.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-2a-3.jpg)
3. Set the app name and logo. You may wish to tick the **Do not display application to users** if you would like to enable the app later.
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/image%2B%2831%29-2.png)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/image%2B%2831%29-2.png)
4. You will be presented with a list of options that need to be filled
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/image%2B%2832%29-1.png)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/image%2B%2832%29-1.png)
5. These options come from Toggl, so let’s jump there for a moment in another browser window. Go to Toggl Profile Settings and choose **Create SSO Profile**
6. Set the profile name and the company domain
   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-6a-4.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/google-workspace-6a-4.jpg)

   *Note the ACS URL and the Entity ID - we will use them shortly.*
7. Go back to Okta Settings and use the values obtained from Toggl to fill in the **Single sign-on URL** field using the ACS URL from Toggl and then filling the **Audience URI** using the **Entity ID** from Toggl**.** In addition, set the following parameters: **Name ID format** to **EmailAddress Application username** to **Email**

   **Note**: if you need your users to begin the SSO flow from your side (also known as Identity Provider initiated login) instead of doing so at [`https://accounts.toggl.com/track/sso-login/`](https://accounts.toggl.com/track/sso-login/) you should append `?toggl_product=track` at the end of the "Single sign-on URL" field.

   [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-2a-2.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-2a-2.jpg)
8. Make sure that **Response** field is set to **Signed** in the Advanced Settings. You can leave the rest of the parameters as defaults. Click **Next**
9. You can fill the Feedback section to your liking or leave it empty and click **Finish**
10. You will be presented with a Metadata URL

    [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-3-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-3-1.jpg)
11. Copy the URL, then go back to Toggl SSO Profile settings, tick the **I have access to an IdP metadata URL** and paste the URL.

    [![](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-4-1.jpg)](https://21421994.fs1.hubspotusercontent-na1.net/hubfs/21421994/Knowledge%20Base%20Import/okta-4-1.jpg)
12. Click on **Submit for review**
13. At this point you are done with the configuration. Please allow some time for the Toggl Support team to verify the configuration and that you are eligible to use the selected domain. Once the verification process gets completed, you will be notified by email.