Overview
Okta handles authentication and identity for most of your workforce. Wire it into Rootly and your team signs into Rootly with their Okta credentials, gets automatically provisioned when added to the Okta group, and disappears from Rootly the moment Okta deprovisions them. No shared passwords, no manual user cleanup, no orphaned accounts when someone leaves. Rootly’s SAML SSO and SCIM provisioning aren’t Okta-specific — they work with any SAML 2.0 IdP — but Okta is the most common integration target, and the setup steps below are written specifically for Okta’s admin UI.Sign In With Okta
Auto-Provision Users
Auto-Deprovision
Group Sync
Before You Begin
- In Okta — Super Admin or an equivalent admin role that can create applications, configure SAML, and enable SCIM provisioning.
- In Rootly — an admin role so you can reach Configuration → Integrations → SSO and paste the values from Okta.
Rootly Service Provider Details
These are the values you’ll paste into Okta when creating the Rootly application. Keep this section handy during setup.https://rootly.com/users/saml/authhttps://rootly.com/users/saml/metadatahttps://rootly.com/users/saml/metadata — Okta can ingest this directly to auto-fill the SAML settings.urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress — the user’s email goes in the NameID.HTTP-POST for both request and response.https://rootly.com/scim — the SCIM endpoint Okta provisions users against.Configure SAML SSO With Okta
Rootly ships a pre-built application in the Okta App Catalog. Install it instead of creating a generic SAML 2.0 app from scratch — the catalog version ships with all SAML attribute mappings, application username defaults, and SCIM endpoints pre-configured.Install The Rootly App From Okta's Catalog
Rootly; if you run multiple Rootly organizations, name each one after its org). Click Next.Copy The Okta IdP Values
- Identity Provider Single Sign-On URL (Okta’s SSO endpoint)
- Identity Provider Issuer (Okta’s Entity ID)
- X.509 Certificate — download the PEM-encoded certificate
Configure SSO In Rootly
-----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines. Add the email domains your team uses (e.g., acme.com) so Rootly knows which logins to route through Okta. Save.Assign The App To Users In Okta
Enable SCIM Provisioning With Okta
SAML handles the sign-in flow. SCIM handles user lifecycle — creating, updating, and deactivating Rootly accounts as Okta assignments change.Copy The Rootly SCIM Token
https://rootly.com/scim.Enable API Integration In The Okta App
Enable Create And Deactivate Users
- Create Users — provisions users when assigned to the Rootly app
- Deactivate Users — removes users from Rootly when unassigned
Push and Link Groups (Optional)
Configure SCIM Group Role Assignment (Optional)
Attribute Mapping Reference
The Rootly catalog app pre-configures these mappings for you. This section is a reference for what Rootly reads from SAML assertions and SCIM payloads — useful for verifying provisioning behavior or troubleshooting attribute gaps. Email is required (sourced from the SAML NameID); the rest are optional but recommended.emailAddress format). Also the unique identifier Rootly uses to match SCIM provisioning calls to existing users.user.firstName.user.lastName.user.displayName.user.primaryPhone.Phone number provisioning via SCIM is off by default and needs to be enabled per team by Rootly support — contact your account team if you want to sync phone numbers alongside user attributes. Without it, users add their own phone numbers in Rootly under their user settings.Test the Integration
After saving SSO in Rootly and assigning the app in Okta, verify the end-to-end flow.Sign In Via Okta
Verify SCIM Provisioning
Verify Deprovisioning
Troubleshooting
Okta redirects but Rootly returns a SAML error
Okta redirects but Rootly returns a SAML error
- The certificate pasted into Rootly is the exact PEM contents Okta provided, including the
-----BEGIN CERTIFICATE-----and-----END CERTIFICATE-----lines - The certificate isn’t expired (Rootly rejects expired certificates at save time)
- The SAML Audience URI in Okta matches
https://rootly.com/users/saml/metadataexactly — trailing slashes and capitalization matter
Users can sign in but no profile fields populate
Users can sign in but no profile fields populate
name.givenName, not name.givenname).SCIM test connection fails with 401
SCIM test connection fails with 401
Users provision but don't have the right role
Users provision but don't have the right role
Deactivation isn't happening when users are unassigned
Deactivation isn't happening when users are unassigned
Login works for some users but not others
Login works for some users but not others
Frequently Asked Questions
Do I need both SSO and SCIM?
Do I need both SSO and SCIM?
Can I use Okta with other Rootly integrations like Slack?
Can I use Okta with other Rootly integrations like Slack?
What happens if Okta is down?
What happens if Okta is down?
Does Rootly support Okta's just-in-time provisioning without SCIM?
Does Rootly support Okta's just-in-time provisioning without SCIM?
Can SCIM and Google Directory Sync run at the same time?
Can SCIM and Google Directory Sync run at the same time?