Skip to main content

Okta SSO Setup Guide

Use this guide to enable Single Sign-On (SSO) using the OIDC protocol for an individual Alteryx Analytics Cloud (AAC) workspace using Okta.

Required Permissions

To enable SSO with Okta, you must satisfy these requirements:

  • Be a user on a Professional or Enterprise AAC plan.

  • Have a Workspace Admin role assigned to you.

  • Have administrative access in the target Okta instance.

Okta Setup

Follow these steps to create an OIDC app integration in Okta:

  1. Sign in to your AAC workspace.

  2. Go to Profile menu > Workspace Admin > Single Sign-On.

  3. Note and copy the prepopulated Callback URL. You will use this later.

  4. Sign in to your Okta Portal as an administrator.

  5. Under Applications, select Applications.

  6. Select Create App Integration.

  7. Select OIDC - OpenID Connect.

  8. Select Web Application.

  9. In the App Integration Name field, enter a name for your app. For example, the name of your AAC workspace.

  10. In the Sign-in redirect URIs field, enter the Callback URL you copied from AAC.

  11. Under Assignments, select the appropriate Controlled Access option based on your organizational requirements.

  12. Select Save.

  13. Note and copy your Client ID. You will use this later.

  14. Note and copy your Client Secret. You will use this later.


Return to your AAC workspace and then follow these steps:

Configure SSO

  1. Go to Profile menu > Workspace Admin > Single Sign-On.

  2. In the Client ID field, enter the Client ID you copied from your Okta account.

  3. In the Client Secret field, enter the Client Secret you copied from your Okta account.

  4. In the Email Mapping OIDC Attribute field, enter this value:

  5. In the Discovery Endpoint field, enter this value:
  6. Next to the Discovery Endpoint field, select Import From URL. The rest of the fields will auto-populate.

  7. Select Save.

Test Connection

  1. Select Test Connection. A dialog then opens, prompting you to sign in to verify the integration.

  2. Enter your Okta credentials. The dialog automatically closes if the integration has been verified.

Enable SSO

  1. Select Enable SSO.

  2. Select Confirm. Once enabled, users can only sign in to your workspace using their Okta credentials.