Okta SSO integration
Connect your Alpacon workspace to Okta using the Okta Integration Network (OIN). The Alpacon OIN app uses OpenID Connect (OIDC) with Express Configuration, so a single click sets up the connection, with nothing to configure by hand.
Once connected, your team signs in to Alpacon with their Okta credentials, and you manage who has access to Alpacon directly from Okta.
Prerequisites
Before you begin, make sure you have:
- An Alpacon workspace on the Enterprise plan
- The superuser role in your Alpacon workspace
- Administrator access to your Okta org
Supported features
The Alpacon Okta integration supports the following features:
- SP-initiated SSO: start sign-in from your Alpacon workspace URL
- IdP-initiated SSO: start sign-in from the Alpacon tile on your Okta dashboard
- Just-In-Time (JIT) provisioning: new users are created in Alpacon on first sign-in
For definitions of these terms, see the Okta glossary.
Configuration steps
Step 1: Add Alpacon from the OIN catalog
- Sign in to your Okta Admin Console.
- Go to Applications → Browse App Catalog.
- Search for Alpacon and open the integration.
- Click Add Integration.
Step 2: Run Express Configuration
Alpacon uses Express Configuration to set up the OIDC connection automatically.
- On the Alpacon app page in Okta, click Express Configuration.
- Enter the Alpacon workspace you want to connect.
- Sign in to that workspace as a superuser to approve the connection.
The connection is set up automatically, with nothing to copy or paste by hand. Okta also links the dashboard tile to your workspace, so users sign in to the correct workspace from the start.
Step 3: Assign users
- Open the Alpacon application in Okta.
- Go to Assignments → Assign → Assign to People or Assign to Groups.
- Select the users or groups that need access to Alpacon.
- Click Done.
Assigned users can now sign in to Alpacon with Okta. New users are created in your Alpacon workspace automatically the first time they sign in.
SP-initiated SSO
Alpacon sign-in is scoped to a workspace, so start from your workspace URL rather than the Alpacon home page:
- Go to
https://alpacon.io/<workspace>(for example,https://alpacon.io/myworkspace). - You’re taken to the sign-in screen for that workspace, where Continue with Okta appears.
- Click it to authenticate with Okta.
- After authenticating, you’re returned to your Alpacon workspace, signed in.
The Okta option appears only on a workspace sign-in screen. The generic sign-in screen at alpacon.io carries no workspace context, so Alpacon cannot tell which Okta org to send you to and offers email and password sign-in only.
To start sign-in from Okta (IdP-initiated), click the Alpacon tile on your Okta dashboard.
Troubleshooting
- No Alpacon tile after assignment: confirm the user, or a group they belong to, is assigned to the Alpacon app in Okta.
- “Continue with Okta” is missing on the sign-in screen: confirm you started from your workspace URL (
https://alpacon.io/<workspace>) and not from alpacon.io. The Okta option is shown only once the workspace is known. If it’s still missing on the workspace sign-in screen, the connection may not have finished setup—re-run Express Configuration. - Wrong workspace after sign-in: make sure you used the Alpacon tile set up by Express Configuration.
If the problem persists, contact Alpacon Support.