Configure SAML in Okta

This guide describes the steps required to create a working SAML integration between Okta and GoBright.

We recommend opening two browser windows side by side, because you’ll need to switch between the two.

Steps to configure Okta & GoBright SAML

1. In the Okta admin panel

1.1 Go to ‘Applications’ > ‘Applications’.
1.2 There click ‘Create App Integration’:

1.3 Choose ‘SAML 2.0’:

1.4 Enter the name, and do not display the app to users:

1.5 Hit ‘Next’ and fill in the ‘Configure SAML page’.

2. In the GoBright Portal

2.1 Create the SAML integration, and take the following values:

  • Obtain the ‘Reply URL (Assertion Consumer Service URL)’
  • Obtain the ‘Relying party identifier / Entity Id’

3. Back in the Okta admin panel

3.1 Paste the obtained Reply URL into the ‘Single sign-on URL’ field

3.2 Paste the obtained Relying party identifier’ into the Audience URI (SP Entity ID) field

3.3 The other fields in Okta should be configured as:

  • ‘Default RelayState’: keep empty
  • ‘Name ID format’: select ‘Unspecified’
  • ‘Application username’: select ‘Okta username’
  • ‘Update application username on’: select ‘Create and update’

3.4 In the list ‘Attribute Statements’, add:

ATTRIBUTE STATEMENT VALUE REQUIRED
name user.displayname OR
user.firstName + ” ” + user.lastName
yes
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/mobilephone user.mobilePhone no
gobright.pincode [your pincode field] no
gobright.nfc [your nfc field] no
gobright.defaultcostcenteridorname [your default costcenter field] no

The result should look like this:

3.5 Now save the application.
The Sign On-tab will open automatically.

3.6 Scroll down on that Sign On-tab, and click View SAML setup instructions

3.7 Obtain the following details from Okta

  • Obtain the Identity Provider Single Sign-On URL
  • Obtain the X.509 Certificate

4. Final steps in the GoBright Portal

4.1 Apply the obtained values in the SAML integration in the GoBright Portal:

  • Paste the ‘Identity Provider Single Sign-On URL in the ‘Single Sign-on service URL’ in the GoBright Portal
  • Paste the ‘X.509 Certificate in the ‘Token-signing certificate (Base64)’ in the GoBright Portal

Optional: GoBright as ‘bookmark app’ in Okta
To show the ‘GoBright’ app as icon, follow: https://help.okta.com/en-us/Content/Topics/Apps/apps-create-bookmark.htm

This article comes from the Help Center of GoBright.

View original article
Join GoBright at Orgatec 2026

Visit us at Germany's biggest trade fair for workplace and contract environments!

Click here to learn more.
Visual of Cologne city center