Single Sign On (SSO)
Single Sign-On (SSO)
This guide walks through configuring Okta as your Reimbi Single Sign-On (SSO) provider. For general background on how SSO works in Reimbi, see the SSO overview.
Okta Configuration
Create a New Application Integration
- Navigate to https://your-okta-instance.okta.com/admin/apps/active
- Click the "Create App Integration" button
- Select SAML 2.0 as the sign-on method

Configure SAML Integration
Set up the basic application details:
- App name: Reimbi
- Logo: https://www.reimbi.com/branding

Configure SAML Settings
Configure the SAML integration with the following settings:
- Single sign on URL: Found in Reimbi Company Settings -> SSO tab
- Audience URI: Found in Reimbi Company Settings -> SSO tab

Assign Users
Navigate to the Assignments tab in Okta to assign users to Reimbi.

Reimbi Configuration
Set Up Metadata URL
- Navigate to Company Settings, open the Integrations page, and click the Configure link next to Okta.

- Locate the Identity Provider metadata URL field
- Enter the URL provided by Okta (found in the Sign on tab of Okta application settings)

Permission Management
Default Permissions
Configure default permissions for new staff users in the Company Settings:
- Navigate to Company Settings -> SSO tab
- Select the default permissions for new users
- Save your changes

Important: Changes to default permissions only affect new users and have no impact on existing staff accounts. Individual permission modifications can be made as needed through Company Settings -> Staff accounts.
