About this page
This page explains how to use Okta as an IdP and set up SAML integration with ZUNDA ID. Once you complete this setup, users signed in to Okta can use those credentials to log in to ZUNDA ID via single sign-on.
What you'll need
Make sure you have the following ready in advance.
-
An Okta user with permission to create and manage application integrations
You need the Okta Super Admin or Application Admin role.
-
A ZUNDA ID user with authentication method admin permissions
You need a user with ZUNDA ID admin permissions to create and configure the SAML provider.
-
A recovery key issued and stored in advance
To prevent a lockout caused by a misconfiguration or an IdP outage, see How to Configure Recovery Settings for Login Methods and issue a recovery key in advance.
Setup steps
You'll switch back and forth between ZUNDA ID and the Okta Admin Console. It's easiest to keep both open at the same time.
Open the Login Method Settings screen in ZUNDA ID, and add a SAML Provider.
Enter a display name of your choice (for example, Okta), and click Create to proceed to the next screen.
On the provider details screen that appears, click Download next to Metadata URL (SP) to download the SP metadata XML.
Log in to the Okta Admin Console (<your-domain>-admin.okta.com), open Applications → Applications from the left menu, and click Create App Integration.
In the Create a new app integration dialog, select SAML 2.0 as the sign-in method, and click Next.
Choosing SAML 2.0 instead of OIDC takes you to a screen where you can configure the SAML parameters in the following steps.
Under general settings, enter a recognizable app name such as ZUNDA ID, and click Next.
The app name you enter here is shown on the Okta dashboard. You can optionally upload an app logo to make it easier for users to identify when launching the app from the dashboard.
On the Configure SAML screen, enter the following parameters.
These parameters must match the values ZUNDA ID publishes as the SP.
- Single sign-on URL
https://id.zunda.co.jp/auth/saml/acs - Audience URI (SP entity ID)
https://id.zunda.co.jp/saml/sp - Name ID format
EmailAddress - Application username
Email address
These values are also included in the SP metadata XML you downloaded earlier from ZUNDA ID, so refer to it if needed. Once you've entered everything, click Next at the bottom of the screen.
On the feedback screen, check This is an internal app that we have created, and click Finish to create the app integration.
Checking this box skips Okta's app integration review process, so you can start using the app internally right away.
Open the Sign On tab of the app you created, open the metadata URL shown in the Metadata details section in your browser, and either copy the XML contents or save them as an XML file.
This metadata includes Okta's IdP certificate, SSO URL, entity ID, and more — importing it into ZUNDA ID lets you bring in all of these IdP-side settings at once. Because ZUNDA ID doesn't support specifying a metadata URL directly, you need to prepare either the raw XML text or an XML file.
Return to the provider details screen in ZUNDA ID, and click Import Metadata XML.
In the dialog that appears, click Upload from file and select the Okta metadata XML file you saved earlier. Once you confirm the IdP Entity ID and SSO URL appear in the preview, click Import Metadata XML.
Registering the SP certificate
This step isn't required, but registering the ZUNDA ID SP certificate with Okta and enabling AuthnRequest signature verification lets Okta cryptographically verify that a request genuinely came from the SP (ZUNDA ID), strengthening protection against impersonation and request tampering.
From the Okta provider details screen in ZUNDA ID, click Download in the SP Certificates section to save the SP certificate file.
Back in Okta, go to the Sign On tab of the app you created, and click Edit next to SAML Settings.
Editing the SAML settings lets you perform additional configuration, such as uploading a signing certificate or adding attribute statements.
Leave the General Settings screen as-is and click Next.
Scroll down the Configure SAML screen, click Browse Files under Signature Certificate, and upload the SP certificate you downloaded from ZUNDA ID earlier.
The uploaded certificate is used to verify the signature of AuthnRequests Okta receives. This lets Okta confirm the validity of the request.
Confirm that the certificate was uploaded and its details (issuer, expiration date, etc.) are shown on screen, then click Next.
On the feedback screen, check This is an internal app that we have created, and click Finish to save.
This completes the signature verification setup. Next, you'll configure the user attribute mapping.
Configuring attribute statements
Configure the user attributes (last name, first name, display name) that Okta sends to ZUNDA ID during SAML login. Without this setting, ZUNDA ID can't correctly import the user's name during JIT sign-up.
Open the General tab of the app, and click Add Another in the Attribute Statements section.
The attribute statements you configure here define the mapping for the user information (last name, first name, display name) Okta sends to ZUNDA ID when the user logs in via SAML. This lets ZUNDA ID receive the correct user information during JIT sign-up.
Add the following three attributes (last name, first name, display name). Select URI Reference for Name format in every case, and make sure Name and Value match the schema ZUNDA ID expects.
-
First name (givenname)
- Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- Value:
user.profile.firstName
-
Last name (surname)
- Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- Value:
user.profile.lastName
-
Display name (name)
- Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- Value:
user.profile.displayName
Confirm that all attributes have been added. user.profile.displayName may not be included in Okta's default profile. If it isn't, either add a displayName attribute to the Okta user profile from Directory → Profile Editor, or use an expression such as user.firstName + " " + user.lastName instead.
Running a test
Use the SSO test feature to confirm that everything up to this point is configured correctly. Because the test requires user assignment on the Okta side, go to the Assignments tab in the Okta Admin Console beforehand and assign the test user's account to the app you created.
From the Okta provider details screen in ZUNDA ID, click the Test button.
The Okta login screen opens in another window (or tab). Log in to Okta using the test user's account. If the SAML login succeeds, "SSO login test succeeded" is displayed as shown below, and the setup is complete once the check results for NameID, Email, Surname, and Given name all show green checkmarks (the Display name is optional, so if it isn't set, ZUNDA ID sets it automatically).
If the test fails, check the following:
- Whether the Okta metadata was imported correctly into ZUNDA ID
- Whether the SP certificate downloaded from ZUNDA ID was uploaded on the Okta side
- Whether the Name and Value fields of the attribute statements (givenname, surname, name) match
- Whether the test user's Okta account is assigned to the app you created
Once the test is complete, return to the provider details screen and switch Status to ON to enable SAML login via Okta. Before switching it on, if you plan to use IdP Initiated login, it's a good idea to double-check that the Okta-side app settings (such as the Application Username on the Sign On tab, and the assignments) are configured as intended.
We strongly recommend completing How to Configure Recovery Settings for Login Methods in advance, in case the login method becomes unavailable. Once your setup is complete, see How to Use the SAML Provider You Created as a Login Method to enable it as a login method.