Okta SAML2 SSO: Secure Single Sign-On with Flexopus
Connect Okta to Flexopus via SAML2 and enable your employees to log in securely and centrally – without separate access data for Flexopus.
What is the Okta SAML2 SSO integration?
The Okta SAML2 SSO integration connects Flexopus with Okta as the Identity Provider (IdP) via the SAML2 protocol. SAML2 (Security Assertion Markup Language) is a widely used standard for secure single sign-on (SSO) between enterprise systems.
Upon registration, the user is redirected to Okta, authenticates there with their company login details, and is then automatically logged into Flexopus. Okta only passes the necessary user attributes (such as name, email and department) to Flexopus.
In addition to SSO, an optional SCIM interface can be activated, through which users and groups from Okta are automatically provisioned in Flexopus.
What is the purpose of integration?
The integration ensures that your employees can use Flexopus with the same login credentials they already use for other company applications. This simplifies daily work and significantly reduces the administrative burden for IT teams.
Typical use cases:
- Centralized access management: IT administrators control directly in Okta which users or groups have access to Flexopus.
- Automatic user creation: New employees are automatically created in Flexopus after their first successful SSO login – without manual input.
- Automatic deactivation: If a user is deactivated in Okta or removed from a group, they automatically lose access to Flexopus.
- Group synchronization via SCIM: Groups from Okta can be transferred to Flexopus via SCIM and used there for access management.
How easy is the setup?
Setting up the Okta SAML2 SSO integration takes place in a few steps: In the Okta Admin console, a new SAML2 app integration is created and configured with the corresponding URLs from the Flexopus settings. The metadata file from Okta is then uploaded to Flexopus to establish the connection.
The optional SCIM configuration also enables automatic synchronization of users and groups.
Ready to start? For complete step-by-step setup instructions, please visit our Help Center.
What are the advantages of integration?
- Centralized access management: User rights are managed exclusively in Okta – no additional effort required in Flexopus.
- No separate password required: Employees log in using their usual company login details.
- Multi-factor authentication support: The security policies configured in Okta, including MFA, automatically apply to Flexopus login as well.
- Automatic user setup and deactivation: New employees receive immediate access, departing employees lose it automatically.
- Group synchronization via SCIM: Groups can be synchronized directly from Okta and used for management in Flexopus.
- Data minimization: Flexopus only receives the attributes that are actually needed for operation (name, email, department, etc.).
- Included free of charge: SSO integration is (depending on the chosen plan) part of Flexopus and does not require an additional license.
Further integrations
questions and answers
What data is transferred from Okta to Flexopus?
Flexopus only receives the user attributes necessary for registration and profile creation – including first name, last name, email address and optionally department or job title. Password data is never transmitted.
What happens when an employee is deactivated or deleted in Okta?
If a user is deactivated in Okta or removed from the assigned group, they lose access to Flexopus. With SCIM synchronization enabled, the profile in Flexopus is automatically deactivated, making login impossible.
Can I use SCIM without SAML2 SSO?
Technically possible, but not recommended. Since SCIM writes important fields such as email address and external user ID, inconsistencies can occur without SSO. If you are considering this combination, we recommend that you consult with Flexopus support beforehand.
Does Okta support nested groups?
Flexopus exclusively supports flat group structures. For nested groups, only the first level is synchronized. As a workaround, it is recommended to use dynamic groups in Okta that reference nested groups and automatically group them together.
Does Flexopus support IdP-initiated login via Okta?
Yes, with a workaround. Flexopus converts the IdP-initiated login into an SP-initiated login by configuring the RelayState parameter accordingly. This approach increases security, as classic IdP-initiated logins are vulnerable to man-in-the-middle attacks.

