For the complete documentation index, see llms.txt. This page is also available as Markdown.

Okta

This guide assumes that you have already enabled SCIM in the Datasaur app and want to use Okta as the identity provider for both SAML and SCIM integration.

Integrate SCIM 2.0 on Okta

Enable SCIM provisioning

Start by enabling SCIM provisioning for your existing app that is already configured with SAML.

  1. Open your existing app in Okta.

  2. Go to Settings. The General tab opens by default.

  3. Enable the Enable SCIM provisioning option.

  4. Save the changes.

Enable SCIM Provisioning

Configure the settings

After enabling SCIM provisioning, go to the Provisioning tab.

The sidebar contains the following sections:

  • To App

  • To Okta

  • Integration

Integration settings

  1. Open Provisioning > Integration.

  2. Fill the SCIM connector base URL:

    Replace <datasaur-app-base-url> and <your-team-id> accordingly.

    1. For SaaS Datasaur-hosted, you can use app.datasaur.ai as the <datasaur-app-base>. If you're self-hosted, adjust accordingly based on your domain.

    2. You can find the team ID in the URL. For example, if you are currently on https://app.datasaur.ai/teams/1/projects, your team ID is 1.

  3. Set the Unique identifier field for users to email.

  4. Under Supported provisioning actions, enable:

    1. Import New Users and Profile Updates

    2. Push New Users

    3. Push Profile Updates

    4. Push Groups

  5. For the Authentication Mode, select HTTP Header.

    • Fill the Authorization under HTTP Header section with the API key that you generated before from the Datasaur app.

  6. Click Save.

Provisioning: Integration Settings

Configure To App settings

  1. Open Provisioning > To App.

  2. Enable the following options:

    1. Create Users

    2. Update User Attributes

    3. Deactivate Users

Provision users to Datasaur

You can provision users in two ways:

  • Assign people individually

  • Assign groups

Assign people

You can directly assign users to the Datasaur app. Assigned users are automatically added to the workspace with the default Labeler role, since role mapping is not applied to individual assignments.

  1. Open your app in Okta.

  2. Go to the Assignments tab.

  3. Click Assign > Assign to People.

  4. Select the users you want to add.

  5. Click Done.

Users should appear in the workspace within a few minutes.

Assign groups

You can provision multiple users at once by assigning groups.

Users in assigned groups receive roles based on the group-to-role mapping configured in Datasaur. Every change to the group is automatically updated through push groups.

Before you begin

Make sure group-to-role mapping is already configured in Datasaur. Group names in Okta must exactly match the group names configured in the mapping.

If the groups do not exist yet:

  1. In Okta, go to Directory > Groups.

  2. Create the required groups.

  3. Use the same group names configured in Datasaur.

Assign the groups

  1. Open your app in Okta.

  2. Go to the Assignments tab.

  3. Click Assign > Assign to Groups.

  4. Select the groups you want to add.

  5. Click Done.

  6. Open the Push Groups tab and click Push Groups.

  7. Select a group and click Save or Save & Add Another.

  8. Repeat until all groups are added.

Users from the assigned groups should appear in the workspace within a few minutes with their mapped roles.

Last updated