Okta SSO Spec Sheet
This guide explains details about the Okta SSO available in the Okta Markteplace
Supported features:
-
SP-initiated SSO
-
SAML 2.0 authentication
For general information on SAML setup, see Okta SAML Guidance.
Prerequisites
Before you begin:
-
You must be a Holistiplan firm administrator.
-
Your firm must have SSO Self-Serve enabled in the Holistiplan application.
-
If you do not see SSO options in your Holistiplan settings, contact support@holistiplan.com.
Configuration Steps
Step 1: Obtain Okta Metadata
-
In the Okta Admin Console, navigate to Applications → Applications.
-
Search for "Holistiplan SSO" under the "Browser App Integration Catalog".
- Click the "Add Integration" blue button.
- On the "Sign-On Options" tab, select "SAML 2.0".
- Click "Copy" to copy the "Metadata URL" under "Metadata details".
- Click "Done" to complete your SAML 2.0 setup.
- Open the Metadata URL
-
Save the file locally; it will be uploaded to Holistiplan in a later step.
Step 2: Configure SAML in Holistiplan
-
Log in to Holistiplan as a firm administrator.
-
Navigate to Settings → Security Settings.
-
Scroll down and enable SSO Self-Serve.
-
In the SSO Configuration section, select Okta as your Identity Provider.
-
Click Okta Settings.
-
Click Import from XML, and upload the metadata file downloaded from Okta.
-
Click Submit.
-
Choose whether to:
-
Enable SSO (users can log in via SSO or password), or
-
Enable SSO-only (users can log in only through Okta).
-
SAML Settings Reference
| Setting | Value / Description |
|---|---|
| Single Sign-On URL | https://app.holistiplan.com/sso/complete/saml/ |
| Audience URI (SP Entity ID) | https://app.holistiplan.com |
| Name ID format | EmailAddress |
| Application username | |
| Default RelayState | return_to |
| Response / Assertion Signature | Signed |
Attribute Statements (User Mapping)
| Okta Attribute | Holistiplan Field |
|---|---|
user.email |
Email / Username |
User requirements:
Users must already exist in Holistiplan before they can authenticate via SSO.
Testing and Validation
-
In a private or incognito browser window, navigate to https://app.holistiplan.com.
-
On the Holistiplan login page, select Sign in with SSO.
-
Enter your firm’s registered domain or email, then follow the redirect to Okta for authentication.
-
After successful authentication in Okta, you should be redirected back to Holistiplan and automatically logged in.
-
Verify that your user information (name and email) matches the values configured in your Okta attribute statements.
Troubleshooting tips:
-
Confirm that the user exists in Holistiplan before testing; new users must be provisioned in Holistiplan prior to using SSO.
-
Ensure that the SAML metadata imported into Holistiplan matches the current metadata from Okta.
-
If authentication fails, review your SAML attribute mappings and verify that the Audience URI and SSO URL match
https://app.holistiplan.com.
SP-initiated SSO
The sign-in process is initiated from https://app.holistiplan.com/login/
- From your browser, navigate to the Holistiplan sign-in page.
- Click sign in with sso
- Enter your email address and click sign in
- You will be redirected to Okta. Enter your Okta credentials (your email and password) and click "Sign in with Okta".
If your credentials are valid, you are redirected to the Holistiplan dashboard.
Support
If you encounter issues during setup or testing, contact Holistiplan Support at support@holistiplan.com.