Set up SSO with Okta
My OPSWAT Portal offers an integration with a 3rd-party Single Sign-on Service (SSO).
My OPSWAT Portal uses the secure and widely adopted industry standard Security Assertion Markup Language 2.0 (SAML 2.0), so that you can integrate easily with any large identity provider that supports SAML 2.0.
To get started, go to your identity provider's website and follow the instructions to configure a SSO application for My OPSWAT Portal.
Log into Okta as an Administrator
Navigate to Applications and click on the application you want to configure
From the General tab > SAML Settings > Select Edit button
In the Configure SAML step, select:
- Name ID format = EmailADdress to match username of My OPSWAT Portal
- Attribute Statements (optional):
- Name ID format = EmailADdress to match username of My OPSWAT Portal
In the Configure SAML step, Attribute Statement (Optional), and filling as below image and save.
Access Applications > Application > Sign On > SAML Signing Certificates
Click on Generate new certificate to add new Cert
Click Action at the cert row > Select Activate > Save the certificate
Select Action > View Idp metadata and save this file (Save cert file also)
Contact My OPSWAT support team via Support Service and provide all below info:
Ticket Summary: “Integrate Okta with My OPSWAT Portal”
Description:
Customer Company Name: <your company name>
Domain name: <__opswat.com (It must be a valid domain, if not it will not be accepted)>
Short description for the request ticket:
How many users?
Do you have Organization?
- No: please provide Organization name, email of the first Admin.(We will create an Organization and add the first Admin for this Org, then you can invite user to the Organization)
- If Yes: skip this info
OPSWAT will redirect users to authenticate by the configured IDP based on provided domain name or specific user. Do you have any specific users in IDP with different domain emails?
- If No: skip this info
- If Yes: Please provide a list user emails
Metadata file (Which is downloaded from step #9)
Certìicate file
Waiting response from Support Team, they will provide back to you IdP Start URL
Access to the Application, in the Configure SAML step > Edit and move to General > SAML Settings > Edit
Then use the IdP Start URL is provided at step #11 to correct it in SAML Settings and click Save button.
Now you need to assign people/groups who can access this application on Okta

After the user signs in to My OPSWAT Portal using Single Sign-On (SSO), the Admin must manually invite the user to the Organization, or the user needs to send a request to join. This is required in order to share organization entitlements.