English

>

Okta SAML SSO Setup for Yoffix

How to Configure Okta SAML SSO for Yoffix

Table of Contents

Yoffix supports Single Sign-On (SSO) via Okta using SAML 2.0.

This allows users to sign in to Yoffix using their Okta credentials, ensuring centralized authentication and access control.

For other supported SSO providers please see the dedicated pages

All SSO settings in Yoffix are available under:

Settings → SSO

How to Set Up the Integration

Step 1: Log in to Okta Admin Dashboard

  1. Go to:
    https://<yourdomain>.okta.com

  2. Click Admin in the top right corner.


    Okta SAML Instruction image 1

Step 2: Create a SAML 2.0 Application

Navigate to Applications and click Create App Integration

Okta SAML Instruction image 2-1

Select SAML 2.0 and click Next

Okta SAML Instruction image 2-2

On the General settings tab enter App name (Yoffix) and click Next

Okta SAML Instruction image 2-3

Step 3: Configure SAML Settings

Enter the following values:

  • Single sign-on URL (ACS URL):
    https://api.app.yoffix.com/sso/saml/assert

  • Audience URI (SP Entity ID):
    https://api.app.yoffix.com/sso/saml/metadata

Okta SAML Instruction image 2-4

Attribute Statements (case sensitive)

Add the following attributes:

  • emailuser.email

  • first_nameuser.firstName

  • last_nameuser.lastName

Click Next.

Okta SAML Instruction image 2-5

Select:

I'm an Okta customer adding an internal app

Click Finish.

Okta SAML Instruction image 2-6

Step 4: Assign Users or Groups

  1. Open the Assignments tab inside the Yoffix application.

  2. Assign users or groups who should access Yoffix via Okta SSO.

Only assigned users will be able to authenticate through Okta.

Okta SAML Instruction image 3-1

For example you can assign everyone from your Organisation.

Okta SAML Instruction image 3-2Okta SAML Instruction image 3-3

Configure Okta SSO in Yoffix

After completing the Okta setup:

  1. Go to Settings → SSO in Yoffix.

  2. Select SAML.

  3. Enter the following details from Okta:

  • SSO URL
    (Identity Provider Single Sign-On URL from Okta)

  • X.509 Certificate

You can define up to 10 allowed email domains.

Example:
If your company emails follow the format name@yourorgdomain.com, add:

yourorgdomain.com

Only users with configured domains will be able to authenticate via Okta SSO.

If you're still experiencing issues, contact Yoffix support at support@yoffix.com — our team will assist you.