Single Sign On with BrightonID - Okta
Instructions for how to enable Single Sign On(SSO) with BrightonID and Okta Workforce Identity Cloud to enable login to Brighton Customer Hub and other services
Below are the instructions to add your organizations Okta on to BrightonID. At the end of the document there are a is a link to send the appropriate info to our support team to enable it.
-
To connect your Okta tenant as an identity Provider in Auth0, you must create an OIDC application. In your Okta Admin Dashboard, create a new application.
Select Applications > Applications, and Create App Integration.
-
Select Create App Integration.
Choose OIDC as the Sign-in method. Choose Web Application as your Application Type.
- Select Next.
- Enter "BrightonID - Brighton Science" for the App integration name.
- Next, you will enter two (2) redirect URIs in the Sign-in redirect URIs section
- In the first box, enter:
- https://login.brighton-science.com/login/callback
- Click the "+ Add URI" button
- In the next box, enter:
- https://clerk.brighton-science.com/v1/oauth_callback
- https://clerk.brighton-science.com/v1/oauth_callback
- In the first box, enter:
- Select the appropriate option for your organization under Assignments > Controlled Access
- Leave the rest of the fields as default values
- Click Save.
- Take note of the Client ID and Client Secret. You will need to provide these to Brighton Science
- With that complete, send us the information we need to enable your Single Sign On. This information includes:
REQUIRED INFO:
-
- ClientID(example: 9cb7e54e-c1fe-483c-8286-750b11cf4ce0)
- This is an id that you saved from the previous creation process.
- Client Secret(example: MgR8Q~gBK12yW.~pCOsKvEtydyDda82hg7axFawc)
- This is a secret that you saved from the previous creation process.
- Okta domain(example: example.okta.com)
- More information can be found here: Okta Domain
- Email Domain(s)(Example: brighton-science.com, btglabs.com)
- These are an e-mail domains your users may use for their e-mail addresses. This is what we use to detect a user from your org and authenticate them with your process, so you only need to include e-mail domains your users would use.
- ClientID(example: 9cb7e54e-c1fe-483c-8286-750b11cf4ce0)
-
Our support team will configure your environment and reach out to you to test and complete the process.
- After setup is complete, your users will see our standard login page. After entering their e-mail the page removes the password:
- Upon clicking "Log In", they will either:
- be logged in automatically(if they are already logged into Okta with an active session, per your tenant settings) or
- Will see your Okta login screen to login
- After login they will be re-directed to the Brighton Science resource.