Set up Spendesk SAML SSO login on Okta or OneLogin
Connect Spendesk to your Okta or OneLogin identity provider so employees can sign in with SAML single sign-on (a shared login across your company's tools). For: Account Owners and Admins setting up authentication on Growth and Premium plans, or with the SAML SSO add-on.
Before you start
SAML SSO comes automatically with certain billing plans, or as a paid add-on on others.
Ask your Spendesk account or billing manager to activate SAML SSO for your organisation. They will give you your Organisation ID, which you'll enter as the Customer ID in your Okta or OneLogin application.
SAML SSO is activated per organisation, not per company. All companies under one organisation share the same SAML integration.
Every user must already have a Spendesk account before they can sign in through Okta or OneLogin. Spendesk does not support automatic user creation or removal (see Troubleshooting below).
You need Admin access to your Okta or OneLogin account to complete this setup.
👥 Only Account Owners and Admins can request SAML SSO activation and configure the identity provider connection.
Supported features
IdP-initiated SSO: connecting to Spendesk from your Okta or OneLogin homepage.
SP-initiated SSO: connecting via Okta or OneLogin from the Spendesk login page.
Enforced SAML ("Big bang"): when enabling SAML SSO, you can choose to enforce it so users can only log in via SAML, not with a username and password.
For more information on these terms, visit the Okta Glossary.
⚠️ Spendesk's Okta and OneLogin integrations do not support user provisioning (automatic account creation, deletion, Just-In-Time provisioning, or SCIM). Invite users to your Spendesk organisation before they try to connect or sign up via Okta or OneLogin.
Set up Spendesk with Okta
Spendesk is listed as an official partner connector in Okta's marketplace of applications.
Add the Spendesk application
Log in to your Okta admin account.
Navigate to Applications > Applications.
Click Browse App Catalog.
Search for Spendesk.
Click Add Integration.
Enter a name for your application.
Click Done.
Enter your Customer ID
Navigate to the Sign On tab.
Click Edit.
Scroll to Advanced Sign-on Settings.
Enter your Organisation ID in the Customer ID field.
Click Save.
Share the metadata URL
On the Sign On tab, copy the Metadata URL.
Send the Metadata URL to your Spendesk account or billing manager.
Wait for your account or billing manager to confirm SAML SSO activation for your organisation.
💡 You can ask your account or billing manager to enforce SAML for your organisation. This means users can only log in via SAML, not with a username and password.
Assign users and map attributes
Navigate to the Assignments tab.
Assign the users who should access Spendesk through this application.
Confirm the following 3 attributes are mapped for each user:
email(used as the Username)firstNamelastName
⚠️ If you enforce SAML login, Spendesk does not provide a backup sign-in URL for username and password login. Contact Spendesk support via Chat if you need to disable enforcement or turn off SAML.
Set up Spendesk with OneLogin
Spendesk is listed as an official partner connector in OneLogin's marketplace of applications.
Contact your Spendesk account manager to request SAML SSO activation and to receive your Organisation ID.
Log in to OneLogin as an Admin.
Navigate to Applications.
Add the Spendesk connector template.
Enter your Organisation ID in the Spendesk Customer ID field.
Click Save.
Copy the XML metadata file for the application.
Send the XML metadata file to your Spendesk account manager.
Wait for your account manager to confirm the SAML SSO setup is complete.
Test your SAML SSO login using this test link.
Choose whether to enforce SAML SSO for all users, once testing is successful.
Sign in with SAML SSO (SP-initiated)
Navigate to the Spendesk login page.
Click the SAML SSO button.
Enter your email address.
You'll be redirected to your identity provider (Okta or OneLogin) to sign in.
Once your credentials are validated, you'll be redirected to your Spendesk dashboard.
Troubleshooting
Symptom: A new hire can't sign in via Okta or OneLogin, even though SAML SSO is active.
Cause: Spendesk's SAML integrations don't support automatic user provisioning (SCIM or Just-In-Time provisioning).
Resolution: Invite the user to your Spendesk organisation manually before they attempt to sign in through your identity provider.
Symptom: A user is permanently locked out and has no way to log in with a username and password.
Cause: Your organisation has SAML SSO enforced ("Big bang"), and Spendesk provides no backup login URL when enforcement is active.
Resolution: Contact Spendesk support via Chat to temporarily disable SAML enforcement, or to reset SSO for that specific user.
Symptom: A user's SAML login fails or their identity doesn't resolve correctly.
Cause: The user's email address doesn't match between Spendesk and your identity provider, or the required attributes (email, firstName, lastName) aren't mapped correctly.
Resolution: Confirm the user's email address is identical in both systems, and check the attribute mapping in your Okta or OneLogin application.
