{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-user-guide/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"redocly_category":"User Guide","type":"markdown"},"seo":{"title":"Okta SAML 2.0 setup for Lusha SSO","description":"Access documentation, use cases, and technical guides for Lusha. Learn how to query our comprehensive dataset of business profiles and company information using our three main endpoints.","siteUrl":"https://docs.lusha.com","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"okta-saml-20-setup-for-lusha-sso","__idx":0},"children":["Okta SAML 2.0 setup for Lusha SSO"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This guide is for organisations that have created a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["custom SAML 2.0 app from scratch"]}," in Okta — not the pre-built Lusha app from the Okta Integration Network. If you added Lusha directly from the Okta app gallery, use ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/security/how-to-set-up-sso-single-sign-on"},"children":["How to set up SSO (single sign-on)"]}," instead."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["At the end of these steps you'll have a working SSO connection. Step 3 covers exactly where to find the XML metadata file Lusha needs — the part most people get stuck on."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Only Lusha ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Admins"]}," or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Managers on a Scale plan"]}," can enable SSO. You'll also need admin access to your Okta organisation."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"before-you-start","__idx":1},"children":["Before you start"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Have these values ready — you'll enter both into Okta during setup:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single sign-on URL (ACS URL):"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://dashboard-services.lusha.com/v2/sso-okta"},"children":["https://dashboard-services.lusha.com/v2/sso-okta"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Audience URI (SP Entity ID):"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://dashboard-services.lusha.com/v2/sso-okta"},"children":["https://dashboard-services.lusha.com/v2/sso-okta"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-1-create-a-saml-20-app-in-okta","__idx":2},"children":["Step 1: Create a SAML 2.0 app in Okta"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign in to your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta Admin Console"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Applications"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Applications"]},", then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create App Integration"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML 2.0"]}," as the sign-in method and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter an app name (for example: \"Lusha\") and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-2-configure-saml-settings","__idx":3},"children":["Step 2: Configure SAML settings"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configure SAML"]},", fill in the following fields:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single sign-on URL (ACS URL):"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://dashboard-services.lusha.com/v2/sso-okta"},"children":["https://dashboard-services.lusha.com/v2/sso-okta"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Audience URI (SP Entity ID):"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://dashboard-services.lusha.com/v2/sso-okta"},"children":["https://dashboard-services.lusha.com/v2/sso-okta"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name ID format:"]}," EmailAddress"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application username:"]}," Email"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Scroll to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Attribute Statements"]}," and add these three rows:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Name: ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["email"]}," | Format: Unspecified | Value: ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["user.email"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Name: ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["firstName"]}," | Format: Unspecified | Value: ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["user.firstName"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Name: ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["lastName"]}," | Format: Unspecified | Value: ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["user.lastName"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The attribute names must be lowercase and exactly as shown — Lusha's SAML parser is case-sensitive."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},". Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["I'm an Okta customer adding an internal app"]},", then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Finish"]},"."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-3-get-your-xml-metadata-from-okta","__idx":4},"children":["Step 3: Get your XML metadata from Okta"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This is where most users get stuck. Here is exactly where to find the XML file:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the app page, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sign On"]}," tab."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Scroll to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SAML Signing Certificates"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Actions"]}," next to the active certificate → select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["View IdP metadata"]},". The raw XML opens in a new browser tab."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select all (Ctrl+A on Windows, Cmd+A on Mac) and copy the content."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you don't see an active certificate, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Generate new certificate"]}," in that section, set it to active, then repeat the steps above."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-4-connect-to-lusha","__idx":5},"children":["Step 4: Connect to Lusha"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Lusha dashboard"]}," → ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Account and Settings"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enable the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta"]}," toggle."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Paste the XML you copied from Okta into the SAML field."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Test SSO"]},". Lusha runs a real sign-in against the metadata and only shows ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["SSO test passed"]}," once it actually works — nothing is enforced on your team until you connect."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Once the test passes, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connect"]},". You'll see a confirmation that the connection is active."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-5-assign-users-in-okta","__idx":6},"children":["Step 5: Assign users in Okta"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In Okta, go back to the Lusha app and click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assignments"]}," tab."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assign"]}," and choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assign to People"]}," or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Assign to Groups"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Save your assignments."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Done! Your team can now sign in to Lusha using their Okta credentials."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{"className":"callout-warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["⚠️ Warning: If you rotate or regenerate your signing certificate in Okta, repeat Steps 3 and 4 — SSO will stop working until the updated XML is pasted into Lusha and passes ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Test SSO"]}," again."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"related-articles","__idx":7},"children":["Related articles"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/security/how-to-set-up-sso-single-sign-on"},"children":["How to set up SSO (single sign-on)"]}," — for the pre-built Okta Integration Network app"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/security/custom-saml-single-sign-on"},"children":["Custom SAML single sign-on"]}," — for other identity providers"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/team-management/user-roles-and-permissions"},"children":["User roles and permissions"]}]}]}]},"headings":[{"value":"Okta SAML 2.0 setup for Lusha SSO","id":"okta-saml-20-setup-for-lusha-sso","depth":1},{"value":"Before you start","id":"before-you-start","depth":2},{"value":"Step 1: Create a SAML 2.0 app in Okta","id":"step-1-create-a-saml-20-app-in-okta","depth":2},{"value":"Step 2: Configure SAML settings","id":"step-2-configure-saml-settings","depth":2},{"value":"Step 3: Get your XML metadata from Okta","id":"step-3-get-your-xml-metadata-from-okta","depth":2},{"value":"Step 4: Connect to Lusha","id":"step-4-connect-to-lusha","depth":2},{"value":"Step 5: Assign users in Okta","id":"step-5-assign-users-in-okta","depth":2},{"value":"Related articles","id":"related-articles","depth":2}],"frontmatter":{"title":"Okta SAML 2.0 setup for Lusha SSO","description":"Step-by-step guide to connecting Okta to Lusha using a custom SAML 2.0 app, including how to generate and copy the XML metadata file Lusha requires.","seo":{"title":"Okta SAML 2.0 setup for Lusha SSO"}},"lastModified":"2026-07-09T11:47:56.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/user-guide/security/okta-saml-20-setup-for-lusha-sso","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}