---
title: "How to Configure SAML 2.0 for Cobalt"
description: "Configure SAML with Okta using their gallery app for Cobalt."
canonical_url: "https://docs.cobalt.io/articles/how-to-configure-saml-20-for-cobalt-opY0Q2BQLL"
md_url: "https://docs.cobalt.io/articles/how-to-configure-saml-20-for-cobalt-opY0Q2BQLL.md"
---
# How to Configure SAML 2.0 for Cobalt

Configure SAML with Okta using their gallery app for Cobalt.


:::info
This guide is for Organization Owners who configure SAML with Okta as an identity provider (IdP) using the [gallery Cobalt SAML app](https://www.okta.com/integrations/cobalt/).

If you want to [create a non-gallery application for Okta](https://help.okta.com/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_SAML.htm?cshid=ext_Apps_App_Integration_Wizard-saml) manually, see [how to set up the configuration](https://docs.cobalt.io/en-us/articles/configure-saml-sso-oT8Q3qO09D#h-okta).

:::

If your organization [enforces SAML](https://docs.cobalt.io/en-us/articles/configure-saml-sso-oT8Q3qO09D#h-enforce-saml-sso) in Cobalt, users will no longer be able to authenticate through the sign-in page. They must authenticate to Cobalt only through the Okta service.

## **Contents**

* Supported Features
* Configuration Steps
* Notes

## **Supported Features**

The Okta/Cobalt SAML integration supports the following features:

* IdP-initiated SSO

For more information on the listed features, visit the [Okta Glossary](https://help.okta.com/en/prod/Content/Topics/Reference/glossary.htm).

## **Configuration Steps**


1. Sign in to Cobalt, and go to **Settings** > **Identity & Access**. You should have an [Organization Owner](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-owner) role.
2. Under **Configure SAML**, click **Configure**. An overlay for configuring SAML opens

 ![](https://docs.cobalt.io/api/attachments.redirect?id=9bcd2ad9-2ee4-4228-a757-c259e357d73a)


3. In Cobalt, enter the following values from Okta. In the Okta Admin Dashboard, select the **Sign On** tab for the Cobalt SAML app, then click **Edit**. Under **Metadata details**, click **More details**.

* **IdP SSO URL**: Enter the **Sign on URL** from Okta.
* **IdP Certificate**: Enter the **Signing Certificate** from Okta.
* Click **Save Configuration**.

 ![](https://docs.cobalt.io/api/attachments.redirect?id=4be5ade1-7b45-4032-91cb-e17b891d63e8)


4. In Okta, select the **Sign On** tab for the Cobalt SAML app, then click **Edit**.

* **Region**: Enter your region, if applicable. The slug appears in the subdomain of the ACS URL.


:::info
* **Note**: the default value is `us`.

:::

* **Slug**: Enter your organization’s slug from Cobalt. The slug appears after `= `in the ACS URL. You can also find the slug in **Settings** > **General**.

 ![](https://docs.cobalt.io/api/attachments.redirect?id=13b13ff0-9fb7-4159-a79f-bb75de1e51c0 " =896x85")

**• Application username format**: Select **Email**.  ![](https://docs.cobalt.io/api/attachments.redirect?id=bab36b6c-5f26-4148-ac08-ef2dbf5862a0)

* Click **Save**.


5. Done!


:::info
## **Notes**

The following SAML attributes are supported:

| Name | Value |
|----|----|
| email | user.email |

:::
