Connect DealRoom to Okta so your team signs in to DealRoom with their Okta accounts.
Before you start
You need to be a DealRoom organization admin and an Okta administrator who can create app integrations.
Talk to your Customer Success Manager (CSM) first. See How do I set up SSO with DealRoom?
Keep two browser tabs open, one for DealRoom and one for the Okta Admin Console. You'll copy values between them.
Step 1: Get DealRoom's SAML endpoints
In DealRoom, go to Settings → Authentication.
In the SAML Integration section, click Create SAML Integration.
DealRoom shows its SAML endpoints. Click an endpoint to copy it:
Metadata (Entity ID/Metadata URL):
https://<your-subdomain>.dealroom.net/saml/metadataACS (Assertion Consumer Service):
https://<your-subdomain>.dealroom.net/saml/acs
Keep this tab open. You'll come back to fill in the form in Step 5.
Step 2: Create the app integration in Okta
In the Okta Admin Console, go to Applications → Applications.
Click Create App Integration.
Select SAML 2.0 and click Next.
Enter an app name, for example DealRoom – SSO, and click Next.
Step 3: Configure SAML in Okta
General
Okta field | Value |
Single sign-on URL | DealRoom's ACS (Assertion Consumer Service) URL. Leave Use this for Recipient URL and Destination URL checked. |
Audience URI (SP Entity ID) | DealRoom's Metadata (Entity ID/Metadata URL) |
Default RelayState | Leave blank |
Name ID format | Unspecified |
Application username | Okta username |
Under Show Advanced Settings, make sure Response and Assertion Signature are both Signed (the default) and Signature Algorithm is RSA-SHA256.
Attribute Statements
Add these attribute statements:
Name | Name format | Value |
| Unspecified |
|
| Unspecified |
|
| Unspecified |
|
| Unspecified |
|
Names are case-sensitive. Type them exactly as shown.
Why Id? DealRoom uses this value to recognize each user across sign-ins. The Okta user ID never changes, even when a user's email address or name changes.
Click Next. On the feedback page, select I'm an Okta customer adding an internal app and click Finish.
Step 4: Get Okta's identity provider details
In the app, open the Sign On tab.
Click View SAML setup instructions. The page lists the values DealRoom needs:
Identity Provider Single Sign-On URL
Identity Provider Issuer
X.509 Certificate
Step 5: Finish the integration in DealRoom
Return to the DealRoom tab and fill in the SAML Integration form.
Identity provider settings
DealRoom field | Value |
Title | A name your users will recognize, for example Okta |
Entity ID | Identity Provider Issuer |
Single Sign On URL | Identity Provider Single Sign-On URL |
Single Log Out URL | Identity Provider Single Sign-On URL (the same value as above) |
x509 public certificate | X.509 Certificate, including the |
Note: This setup doesn't use Okta single logout, so the Single Sign-On URL also goes in the required Single Log Out URL field.
Attribute mapping
DealRoom field | Value |
Identifier |
|
| |
First Name |
|
Last Name |
|
Title | Leave blank (optional) |
Phone | Leave blank (optional) |
Click Create to save the integration.
Step 6: Assign users and groups
In Okta, open the app's Assignments tab and click Assign. Assign the people or groups who should sign in to DealRoom with SSO. Users who aren't assigned can't sign in through this app.
Step 7: Test the sign-in
Sign out of DealRoom, then sign in with SSO as a user you assigned in Step 6.
Troubleshooting
Extra spaces or missing characters. Check that no spaces or line breaks were added when you copied the URLs, and that the certificate includes its BEGIN and END lines.
"User is not assigned to this application" in Okta. Assign the user or one of their groups (Step 6).
Sign-in works but the user is not recognized. Check that the
Idattribute statement exists in Okta and that Identifier in DealRoom is exactlyId.
Still stuck? Contact your CSM or email support@dealroom.net.






