Skip to main content

How to configure SSO with Okta in Spendesk?

How to Configure SSO with Okta in Spendesk

Configure SSO with Okta in Spendesk

Set up SAML Single Sign-On (SSO) so your team logs into Spendesk using your Okta account, improving security and simplifying access management.

For: Account Owners and Admins with Okta administrator access. Available on selected plans or as a paid add-on.

Before you start

Requirement

Detail

Role

Account Owner (to request activation) and Okta Administrator (to configure the application)

Plan

SAML SSO is included with certain plans or available as a paid add-on

Setup

Contact your Spendesk account manager to activate SAML SSO and receive your Organisation ID

Scope

SAML SSO applies to your entire organisation, not to a single company, even if you manage multiple companies

User accounts

Every user must already have a Spendesk account (be invited) before they can sign in with Okta

👥 Only Account Owners can request SAML SSO activation from Spendesk. Okta configuration requires Okta Administrator access.

🔒 SAML SSO is not included in all plans by default. Contact your account manager to confirm eligibility and pricing.

Step-by-step configuration

Step 1: Add the Spendesk application in Okta

  1. Log in to your Okta Administrator account.

  2. Navigate to Applications > Applications.

  3. Click "Browse App Catalog".

  4. Search for "Spendesk".

  5. Click "Add Integration".

  6. Enter a name for the application.

  7. Click "Done".

Step 2: Enter your Organisation ID

  1. Open the newly created Spendesk application in Okta.

  2. Navigate to the "Sign On" tab.

  3. Click "Edit".

  4. Scroll to "Advanced Sign-on Settings".

  5. Enter your Spendesk Organisation ID in the "Customer ID" field.

  6. Click "Save".

Step 3: Share your metadata with Spendesk

  1. Stay on the "Sign On" tab.

  2. Copy the "Metadata URL".

  3. Send the Metadata URL to your Spendesk account manager.

  4. Wait for your account manager to confirm that SAML SSO is fully activated.

Step 4: Assign users in Okta

  1. Open the Spendesk application in Okta.

  2. Navigate to the "Assignments" tab.

  3. Click "Assign" and select the users or groups who should access Spendesk via Okta.

⚠️ Choosing to enforce SAML SSO (also called "Big bang") means users can only sign in through Okta. Spendesk does not provide a backup username/password login when enforcement is active. Contact Spendesk support via Chat before enforcing SSO if you need this option reversed.

Log in to Spendesk via Okta

You can connect to Spendesk in two ways once setup is complete:

From Okta (IdP-initiated):

  1. Open your Okta homepage.

  2. Click the Spendesk application tile.

From Spendesk (SP-initiated):

  1. Click "SAML SSO".

  2. Enter your email address.

  3. Sign in when redirected to Okta.

What's supported

Supported

Not supported

IdP-initiated SSO (from Okta)

Auto-provisioning or auto-deprovisioning of user accounts (SCIM)

SP-initiated SSO (from Spendesk login page)

Automatic sync of roles and teams from Okta

Enforcing SAML SSO as the only login method

More than one SSO provider per organisation

💡 Users must be invited to Spendesk before they can sign in via Okta. You can speed this up by sharing a unique sign-up link with new employees instead of inviting them one by one.

Troubleshooting

Symptom: A user cannot sign in and sees an authentication error after being redirected from Okta.
Cause: The user's email address in Okta does not match their email address in Spendesk, or the required attributes (email, first name, last name) are missing.
Resolution:

  1. Confirm the user has an active Spendesk account with a matching email address.

  2. Check your Okta application's attribute mappings for email, first_name, and last_name.

  3. Ask the user to try signing in again.

Symptom: The Spendesk application does not appear on the user's Okta homepage.
Cause: The user has not been assigned to the Spendesk application in Okta.
Resolution:

  1. In Okta, open the Spendesk application.

  2. Navigate to the "Assignments" tab.

  3. Assign the user or their group.

Symptom: SAML SSO setup fails to complete.
Cause: The Organisation ID (Customer ID) or Metadata URL was entered or shared incorrectly.
Resolution:

  1. Verify the Organisation ID matches exactly what your account manager provided.

  2. Re-copy the Metadata URL from the "Sign On" tab and resend it to your account manager.

FAQs

Can I use SAML SSO across multiple companies in my organisation?
Yes. SAML SSO is activated per organisation, so it applies to all companies within that organisation.

Can I turn off SAML SSO after activating it?
Yes. Contact your Spendesk account manager or use the Chat support to deactivate or disable enforcement.

Does Okta automatically create Spendesk accounts for new employees?
No. User auto-provisioning (SCIM) is not supported. Invite users to Spendesk first.

Related articles

Did this answer your question?