Skip to main content

Set up SAML SSO with Okta

Connect DealRoom to Okta so your team signs in to DealRoom with their Okta accounts.

Connect DealRoom to Okta so your team signs in to DealRoom with their Okta accounts.

Before you start

  • You need to be a DealRoom organization admin and an Okta administrator who can create app integrations.

  • Talk to your Customer Success Manager (CSM) first. See How do I set up SSO with DealRoom?

  • Keep two browser tabs open, one for DealRoom and one for the Okta Admin Console. You'll copy values between them.

Step 1: Get DealRoom's SAML endpoints

  1. In DealRoom, go to Settings → Authentication.

  2. In the SAML Integration section, click Create SAML Integration.

  3. DealRoom shows its SAML endpoints. Click an endpoint to copy it:

    • Metadata (Entity ID/Metadata URL): https://<your-subdomain>.dealroom.net/saml/metadata

    • ACS (Assertion Consumer Service): https://<your-subdomain>.dealroom.net/saml/acs

Keep this tab open. You'll come back to fill in the form in Step 5.

Step 2: Create the app integration in Okta

  1. In the Okta Admin Console, go to Applications → Applications.

  2. Click Create App Integration.

  3. Select SAML 2.0 and click Next.

  4. Enter an app name, for example DealRoom – SSO, and click Next.

Step 3: Configure SAML in Okta

General

Okta field

Value

Single sign-on URL

DealRoom's ACS (Assertion Consumer Service) URL. Leave Use this for Recipient URL and Destination URL checked.

Audience URI (SP Entity ID)

DealRoom's Metadata (Entity ID/Metadata URL)

Default RelayState

Leave blank

Name ID format

Unspecified

Application username

Okta username

Under Show Advanced Settings, make sure Response and Assertion Signature are both Signed (the default) and Signature Algorithm is RSA-SHA256.

Attribute Statements

Add these attribute statements:

Name

Name format

Value

Id

Unspecified

user.id

Email

Unspecified

user.email

FirstName

Unspecified

user.firstName

LastName

Unspecified

user.lastName

Names are case-sensitive. Type them exactly as shown.

Why Id? DealRoom uses this value to recognize each user across sign-ins. The Okta user ID never changes, even when a user's email address or name changes.

Click Next. On the feedback page, select I'm an Okta customer adding an internal app and click Finish.

Step 4: Get Okta's identity provider details

  1. In the app, open the Sign On tab.

  2. Click View SAML setup instructions. The page lists the values DealRoom needs:

    • Identity Provider Single Sign-On URL

    • Identity Provider Issuer

    • X.509 Certificate

Step 5: Finish the integration in DealRoom

Return to the DealRoom tab and fill in the SAML Integration form.

Identity provider settings

DealRoom field

Value

Title

A name your users will recognize, for example Okta

Entity ID

Identity Provider Issuer

Single Sign On URL

Identity Provider Single Sign-On URL

Single Log Out URL

Identity Provider Single Sign-On URL (the same value as above)

x509 public certificate

X.509 Certificate, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines

Note: This setup doesn't use Okta single logout, so the Single Sign-On URL also goes in the required Single Log Out URL field.

Attribute mapping

DealRoom field

Value

Identifier

Id

Email

Email

First Name

FirstName

Last Name

LastName

Title

Leave blank (optional)

Phone

Leave blank (optional)

Click Create to save the integration.

Step 6: Assign users and groups

In Okta, open the app's Assignments tab and click Assign. Assign the people or groups who should sign in to DealRoom with SSO. Users who aren't assigned can't sign in through this app.

Step 7: Test the sign-in

Sign out of DealRoom, then sign in with SSO as a user you assigned in Step 6.

Troubleshooting

  • Extra spaces or missing characters. Check that no spaces or line breaks were added when you copied the URLs, and that the certificate includes its BEGIN and END lines.

  • "User is not assigned to this application" in Okta. Assign the user or one of their groups (Step 6).

  • Sign-in works but the user is not recognized. Check that the Id attribute statement exists in Okta and that Identifier in DealRoom is exactly Id.

Still stuck? Contact your CSM or email support@dealroom.net.

Did this answer your question?