Single sign-on

Okta

Use this guide when your organization signs in with Okta. Lettermint connects to an Okta OIDC app integration.

Before you start

You need administrator access to Okta. The sign-in redirect URI configured in Okta must match the Lettermint OIDC callback URL from the SSO guide exactly.

Okta setup

  1. In the Okta Admin Console, create an OIDC - OpenID Connect app integration.
  2. Choose Web Application.
  3. Add the Lettermint OIDC callback URL from the SSO guide as a sign-in redirect URI.
  4. Assign the app to the users or groups that should access Lettermint.
  5. Copy the client ID and client secret.
  6. Note your Okta issuer base URL.

Lettermint setup

In the Lettermint SSO setup screen, choose Okta and enter:

FieldValue
DomainYour managed email domain, for example example.com.
Metadata URLhttps://{tenant}.okta.com/.well-known/openid-configuration
Client IDThe Okta client ID.
Client secretThe Okta client secret.

If you use a custom authorization server, use that issuer's discovery URL instead.

References