AtomationDocsOIN SAML guide

Configure Atomation SAML SSO in Okta

Set up SAML 2.0 single sign-on from Okta to an Atomation workspace. SCIM provisioning is configured separately, and users must be provisioned before first SAML sign-in.

SAML 2.0IdP and SP initiatedNo JITOIN guide

Scope

Atomation supports Okta SAML 2.0 SSO for workspace sign-in. This guide covers the SAML configuration only. Configure SCIM provisioning with the separate Atomation SCIM provisioning guide.

Current OIN submission scope: SAML SSO and SCIM provisioning only. Atomation does not support SAML Just-In-Time provisioning for this submission, and Universal Logout is not part of this submission.

Prerequisites

  • An Atomation workspace with a known tenant subdomain, such as subdomain.
  • An Okta administrator who can add and configure the Atomation integration from the Okta Integration Network.
  • Access to the Atomation workspace SAML settings page, where the workspace-specific ACS, entity ID, and metadata values are shown.
  • SCIM provisioning configured separately before assigning users for first sign-in.

SAML and SCIM apply to one selected Okta identity org per Atomation workspace. Additional Okta orgs connect to Atomation separately for assessment access only.

SAML values

Replace subdomain with the Atomation tenant subdomain provided for your workspace.

Okta SAML fieldValue
Single Sign-On URLhttps://subdomain.atomation.io/auth/saml/acs
Recipient URL / Destination URLhttps://subdomain.atomation.io/auth/saml/acs
Audience URI / SP Entity IDhttps://subdomain.atomation.io/saml/metadata
SP-Initiated Login URLhttps://subdomain.atomation.io/auth/saml/login
Name ID formatUnspecified
Application usernameOkta username
Attribute statementsNo custom SAML attributes required
Group attribute statementsLeave empty; role mapping is handled through SCIM groups

Setup steps

Step 1

Add or open the Atomation integration

For a customer installation, open Applications → Browse App Catalog, find Atomation, and select Add Integration. During OIN review, open the OIN Wizard-generated review instance. Use that catalog or generated instance for both SAML and SCIM setup.

Step 2

Enter the workspace subdomain

Set the integration's Subdomain tenant setting to the Atomation workspace subdomain, such as subdomain. The OIN integration uses that value to generate the ACS URL, Recipient/Destination URL, Entity ID, and SP-initiated login URL shown above. Confirm the resolved URLs use the expected Atomation workspace host.

Step 3

Confirm username and attributes

Confirm Name ID format is Unspecified and Application username is Okta username. No custom SAML attributes or group attributes are required; assign Atomation roles with SCIM Group Push or Group Linking.

Step 4

Copy Okta metadata into Atomation

In the Atomation integration instance, open the Sign On tab and copy the Okta Metadata URL. Paste that metadata URL into the Atomation SAML settings for the same workspace identity org, then save and verify.

Step 5

Assign users after SCIM is ready

Configure SCIM first, then assign users or app-access groups to the Atomation integration. Atomation does not create users from SAML assertions for this submission.

Atomation SAML settings showing workspace-specific SAML URLs.
Atomation SAML settings: copy the workspace-specific ACS URL and Entity ID values.

Test sign-in

  • For IdP-initiated sign-in, launch Atomation from the Okta End-User Dashboard app tile.
  • For SP-initiated sign-in, open https://subdomain.atomation.io/auth/saml/login.
  • For OIN testing, set "Supports Just-In-Time provisioning?" to No.
  • If the Okta OIN Submission Tester is used, run only the IdP and SP SAML flows.

Troubleshooting

  • If sign-in reaches Atomation but access is denied, confirm the user was provisioned by SCIM before sign-in.
  • If SP-initiated sign-in fails before Okta login, confirm the tenant subdomain and SP-init URL are exact.
  • If the SAML response is rejected, refresh the Okta metadata URL in Atomation and verify the same Okta org is the selected workspace identity org.
  • Email [email protected] with the tenant subdomain, Okta app label, timestamp, and failed step.