Configure SSO with Okta
Integrate Okta with Pinecone to enable single sign-on, configure SAML settings, and manage secure user authentication for your organization.
This page describes how to set up Pinecone with Okta as the single sign-on (SSO) provider. These instructions can be adapted for any provider with SAML 2.0 support.
Before you begin
Section titled “Before you begin”This page assumes you have the following:
- Access to your organization's Pinecone console as an organization owner.
- Access to your organization's Okta Admin console.
1. Start SSO setup in Pinecone
Section titled “1. Start SSO setup in Pinecone”First, start setting up SSO in Pinecone. In this step, you'll capture a couple values necessary for configuring Okta in Step 2.
- In the Pinecone console, go to Settings > Access > Identity provider.
- In the Single sign-on section, click Enable SSO.
- In the Setup SSO dialog, copy the Entity ID and the Assertion Consumer Service (ACS) URL. You'll need these values in Step 2.
- Click Next.
Keep this window or browser tab open. You'll come back to it in Step 4.
2. Create an app integration in Okta
Section titled “2. Create an app integration in Okta”In Okta, follow these steps to create and configure a Pinecone app integration:
-
If you're not already on the Okta Admin console, navigate there by clicking the Admin button.
-
Navigate to Applications > Applications.
-
Click Create App Integration.
-
Select SAML 2.0.
-
Click Next.
-
Enter the General Settings:
- App name:
Pinecone - App logo: (optional)
- App visibility: Set according to your organization's needs.
- App name:
-
Click Next.
-
For SAML Settings, enter values you copied in Step 1:
- Single sign-on URL: Your Assertion Consumer Service (ACS) URL
- Audience URI (SP Entity ID): Your Entity ID
- Name ID format:
EmailAddress - Application username:
Okta username - Update application username on:
Create and update
-
In the Attribute Statements (SAML) section, create the following attribute:
- Name:
email - Value:
user.email
- Name:
-
Click Next.
-
Click Finish.
3. Get the sign on URL and certificate from Okta
Section titled “3. Get the sign on URL and certificate from Okta”Next, in Okta, get the URL and certificate for the Pinecone application you just created. You'll use these in Step 4.
-
In the Okta Admin console, navigate to Applications > Pinecone > Sign On. If you're continuing from the previous step, you should already be on the right page.
-
In the SAML 2.0 section, expand More details.
-
Copy the Sign on URL.
-
Download the Signing Certificate.
4. Complete SSO setup in Pinecone
Section titled “4. Complete SSO setup in Pinecone”In the browser tab or window you kept open in Step 1, complete the SSO setup in Pinecone:
-
In the SSO Setup window, enter the following values:
-
Choose whether or not to Enforce SSO for all users.
- If enabled, all members of your organization must use SSO to log in to Pinecone.
- If disabled, members can choose to log in with SSO or with their Pinecone credentials.
-
Click Next.
-
Select a Default role for all users who log in with SSO. You can change user roles later.
Okta is now ready to be used for single sign-on. Follow the Okta docs to learn how to add users and groups.
Manage roles automatically
Section titled “Manage roles automatically”Optionally, you can have Pinecone assign organization and project roles automatically from your identity provider on each login, instead of managing them manually. For more information, see Manage roles with Okta.