Single sign-on · Okta

Okta

Okta publishes a metadata URL we keep reading, so day-to-day it looks after itself. The one thing to plan for is that Okta uses a single signing certificate at a time, which makes a renewal a moment rather than a window.

Setting it up

The step-by-step walkthrough lives in the product, at Organisation settings → Single sign-on. Use it for the actual setup: it shows your live service provider values with copy buttons.

In outline, you will:

  • Start a new app integration in the Okta Admin Console, choosing SAML 2.0.
  • Name it Stable Baseline.
  • Paste our single sign-on URL and audience URI into the SAML settings.
  • Set the Name ID format to EmailAddress.
  • Copy the Identity Provider metadata URL back into Stable Baseline.
  • Assign the people or groups who should have access.

Assignment is your access control

Only people assigned to the app in Okta can sign in. That is usually what you want: removing someone in Okta removes their access here, without you touching Stable Baseline at all.

Certificates and rotation

Okta
MetadataURL, which we re-read automatically
Certificate lifetimeAbout 10 years by default
Rotation styleOne active signing certificate at a time
Do you need to do anything?Yes, at renewal

Okta does not run two signing certificates in parallel the way Entra does. There is one active certificate, and switching to a new one is a single moment rather than an overlap you can drift through.

Because we read your metadata URL daily, we will pick up the new certificate — but if you generate and activate it in one sitting, there is a window between your switch and our next read where sign-ins fail.

Renewing a certificate

  • In the Okta Admin Console, open your Stable Baseline app, then Sign On → SAML Signing Certificates.
  • Generate a new certificate. It will be created in an inactive state.
  • Activate it. This is the moment the change takes effect for everyone.
  • Confirm sign-in still works. If it does not, the fastest fix is to re-save your metadata URL in Stable Baseline, which forces an immediate re-read rather than waiting for the daily one.

Have an owner ready before you rotate

If a rotation does break sign-in and you have enforcement switched on, the only way back in is an organisation owner using their password and two-factor authentication. Worth confirming an owner can do that before you start, not after.

What we will tell you

We email your owners and administrators at 60, 30, 14, 7, 3 and 1 days before the certificate expires, and daily after that. With a ten-year Okta certificate these warnings may be the only reminder anyone gets, so it is worth making sure they reach a shared mailbox rather than one person’s inbox.