---
title: Setting up ZEN Master Okta SSO
slug: zen-master/setting-up-zen-master-okta-sso
docTags: 
createdAt: 2024-12-10T21:00:32.265Z
---

This section includes instructions on how to register ZEN Master as an SSO app on Okta and configure the connection between ZEN Master and Okta. To complete this process, you need to log in as an Admin on both the Okta side and the ZEN Master side. It is, therefore, recommended to have both open in parallel.&#x20;

**To setup ZEN Master Okta SSO**:

::::WorkflowBlock
:::WorkflowBlockItem
On the **Okta&#x20;**&#x68;ome page, Click **Applications**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/t_X81S8q1Q16E2Zup9snx_image.png" size="90" width="1300" height="570" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Add Application**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/1bT02UvA9aTvXIrbtPE54_image.png" size="90" width="1891" height="803" position="center" showCaption="false"}

The **Add Application** screen opens.
:::

:::WorkflowBlockItem
Click **Create New App**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/uoj9ydBfKD_LzpB6RfYZ4_image.png" size="90" width="1341" height="478" position="center" showCaption="false"}

The **Create a New Application Integration** window opens.
:::

:::WorkflowBlockItem
In the **Platform&#x20;**&#x66;ield, select **Web&#x20;**(default).

In the **Sign on method** field, select **OpenID Connect**.

Click **Create**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/lfLq7D92yjA00Zesi3h71_zen-master-okta-sso-setup.png" size="90" width="1976" height="1146" position="center" showCaption="false"}

The **Create OpenID Connect Integration** screen opens.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/x-VVDCiJjFosJ1JvPy9dv_image.png" size="90" width="1892" height="1815" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In the **Application name** field, enter a name for the SSO app. This name will not be shared and is used for administration purposes only. For example, "ZEN Master".
:::

:::WorkflowBlockItem
In the **Application logo** field, you can optionally choose a logo by clicking **Browse files**, and following the prompts.
:::

:::WorkflowBlockItem
In the **ZEN Master UI**, go to **Account Management > Single Sign-On**.
:::

:::WorkflowBlockItem
Click **+Add**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/xM6OyYu6y1oKbTFwI4HUl_image.png" size="90" width="1920" height="565" position="center" showCaption="false"}

The **Create New Single Sign-On** screen opens.
:::

:::WorkflowBlockItem
Copy the **Callback URL** to your clipboard.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/fNX8wSv7EVcr5Yuknrusn_image.png" size="90" width="1701" height="1494" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In **Okta**, on the **Create OpenID Connect Integration** screen, paste the Callback URL in the **Login Redirect URIs** field, and click **Save**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/m29fLk3hcEb7J-OuBoP71_image.png" size="90" width="1892" height="1815" position="center" showCaption="false"}

The application is created, and the Settings screen for the application opens.&#x20;
:::

:::WorkflowBlockItem
Click on the **Assignments&#x20;**&#x74;ab.



::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/Dg0I_sYpIXmX4C55USrD2_image.png" size="90" width="1214" height="921" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Assign**, and then select either **Assign to People** or **Assign to Groups** (depending on how you want to assign access to this App).



::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/RZze-ZI3zbCc4uiAbq5Jy_image.png" size="90" width="1174" height="724" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In the **Assign&#x20;**&#x77;indow that opens, select each user or group that you want to grant access to, by clicking **Assign**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/0m0fZPmvvC7yyojuOSlAN_image.png" size="90" width="1754" height="1475" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Each time that you assign the App to an individual user, a window opens specific to that user, enabling you to optionally modify that user’s profile information.

Click **Save and Go Back**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/3SEedw169f_iu_0ZLicMP_image.png" size="90" width="1758" height="1480" position="center" showCaption="false"}

The user is assigned to the App.
:::

:::WorkflowBlockItem
Click **Done**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/Ft5A_iHbHJYhidckr9pDP_image.png" size="90" width="1757" height="1476" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Click on the **General&#x20;**&#x74;ab, and scroll down to the **Client Credentials** section.

The **Client Credentials** can be found on the bottom of the page. You will need the **Client ID** and **Client secret** from that section to continue the setup process in ZEN Master.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/OlvinDYVzxM9f_cnXeLoP_image.png" size="90" width="1890" height="1065" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Click the **Client ID** copy button.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/1C5IAtV-UzqGUqUybTLOe_image.png" size="90" width="1807" height="782" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In **ZEN Master**, paste the Client ID in the **Client ID** field.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/qfNoYOzx4v8ecuviV1W4k_image.png" size="90" width="1701" height="1494" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Back in **Okta**, copy the **Client secret**, and paste it in the **Client Secret** field in **ZEN Master**.
:::

:::WorkflowBlockItem
In **ZEN Master**, in the **Name&#x20;**&#x66;ield, enter a name for this SSO connection, for example Okta SSO. This is the name that will be displayed on the Okta button in the ZEN Master **Sign In** portal.
:::

:::WorkflowBlockItem
In the **Authorization URL** field, enter your unique authorization URL. For example, https\://\{yourOktaOrg}.okta.com/oauth2/v1/authorize. For more information about Okta Authorization Servers, see [Authorization Servers](https://developer.okta.com/docs/concepts/auth-servers/).
:::

:::WorkflowBlockItem
In the **Token URL** field, enter your unique token URL. For example, https\://\{yourOktaOrg}.okta.com/oauth2/v1/token. For more information about Okta Authorization Servers, see [Authorization Servers](https://developer.okta.com/docs/concepts/auth-servers/).
:::

:::WorkflowBlockItem
If you want to manually register Okta users to ZEN Master (see [Pre-registering Users in ZEN Master for Okta](docId\:fPKG_WrUTQTxG3MdVhK2x)) before granting access, select the **Allow pre-registered users only** checkbox. The registration is simple and only involves entering the user's email.&#x20;
:::

:::WorkflowBlockItem
In **ZEN Master**, click **Save**.
The newly created Okta SSO is added to the list of SSO profiles. The users assigned in Okta will be able to connect to ZEN Master by selecting the newly created SSO option under **Sign In With**. During the first connection you may be required to provide permission to connect through Okta to ZEN Master. As an administrator, you can select **Consent on behalf of your organization** option, which will not require additional consent by the other users.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/QatpDo8jipw0wlZ8VXt3V_image.png" size="90" width="948" height="1017" position="center" showCaption="false"}

However, if you have selected the **Allow pre-registered users only** option you will need to manually pre-register the users by following the instructions below.
:::
::::

